Re: [qubes-devel] QSB #38: Qrexec policy bypass and possible information leak

2018-02-23 Thread 'awokd' via qubes-devel
On Wed, February 21, 2018 11:35 am, 'Tom Zander' via qubes-devel wrote: > The point of a variable that is passed from a VM to the dom0 qrexec > daemon is that your source VM doesn't have to know about who is $adminVM > or what is the actually started dispVM's name. QRexec daemon (in dom0) > should

[qubes-devel] network attach problem after the last updates on 3.2

2018-02-23 Thread Zrubi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, I have a strange problem after updating my system (3.2) from the testing repository. Changing the NetVM of a proxyVM, takes longer time than before, but succeed - at least according to Qubes manager (and qvm tools) But after the change, no traf

Re: [qubes-devel] network attach problem after the last updates on 3.2

2018-02-23 Thread Zrubi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 02/23/2018 11:52 AM, Zrubi wrote: > I have a strange problem after updating my system (3.2) from the > testing repository. > > Changing the NetVM of a proxyVM, takes longer time than before, > but succeed - at least according to Qubes manager (a

Re: [qubes-devel] Possible regression: vm-to-vm RPC calls stopped working

2018-02-23 Thread Yuraeitha
On Thursday, February 22, 2018 at 9:26:42 AM UTC+1, Elias Mårtenson wrote: > On 22 Feb 2018 4:24 pm, "Yuraeitha" wrote: > > Guess I'll draw the long straw, and just get rid of RC-3 and install RC-4 > without confirmation whether it'd any good to do so. I'll probably never find > out the reason,

Re: [qubes-devel] Possible regression: vm-to-vm RPC calls stopped working

2018-02-23 Thread Yuraeitha
On Thursday, February 22, 2018 at 9:26:42 AM UTC+1, Elias Mårtenson wrote: > On 22 Feb 2018 4:24 pm, "Yuraeitha" wrote: > > Guess I'll draw the long straw, and just get rid of RC-3 and install RC-4 > without confirmation whether it'd any good to do so. I'll probably never find > out the reason,

Re: [qubes-devel] Possible regression: vm-to-vm RPC calls stopped working

2018-02-23 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Feb 23, 2018 at 01:27:41PM -0800, Yuraeitha wrote: > On Thursday, February 22, 2018 at 9:26:42 AM UTC+1, Elias Mårtenson wrote: > > On 22 Feb 2018 4:24 pm, "Yuraeitha" wrote: > > > > Guess I'll draw the long straw, and just get rid of RC-3

[qubes-devel] Re: [UPDATE] QSB #37: Information leaks due to processor speculative execution bugs (XSA-254, Meltdown & Sepctre)

2018-02-23 Thread Reg Tiangha
I've noticed that Xen has updated the XSA-254 advisory with Spectre v2 mitigations for Xen 4.6-4.10. I know we'd have to figure out how to backport Retpoline compatible compilers to these various build environments in order to get the full protection (Debian has backported that support to the gcc v

Re: [qubes-devel] Re: [UPDATE] QSB #37: Information leaks due to processor speculative execution bugs (XSA-254, Meltdown & Sepctre)

2018-02-23 Thread 'awokd' via qubes-devel
On Fri, February 23, 2018 10:27 pm, Reg Tiangha wrote: > And a side question about qubes-builder: Does it build in a chroot? I'd > like to attempt to backport a build environment that has a > retpoline-enabled version of gcc, and I'm wondering if I could just bypass > qubes-builder entirely and ru

Re: [qubes-devel] Re: [UPDATE] QSB #37: Information leaks due to processor speculative execution bugs (XSA-254, Meltdown & Sepctre)

2018-02-23 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Feb 23, 2018 at 03:27:38PM -0700, Reg Tiangha wrote: > I've noticed that Xen has updated the XSA-254 advisory with Spectre v2 > mitigations for Xen 4.6-4.10. I know we'd have to figure out how to > backport Retpoline compatible compilers to t

[qubes-devel] Re: [UPDATE] QSB #37: Information leaks due to processor speculative execution bugs (XSA-254, Meltdown & Sepctre)

2018-02-23 Thread Reg Tiangha
On 02/23/2018 04:08 PM, Marek Marczykowski-Górecki wrote: > Simon, can you take a look at it? We'll probably need to put patched gcc > to linux-dom0-updates repository (if newer Fedora has patched gcc and > it's possible to build that src.rpm on older Fedora), or add separate > repository with patc

Re: [qubes-devel] Possible regression: vm-to-vm RPC calls stopped working

2018-02-23 Thread Yuraeitha
On Friday, February 23, 2018 at 10:58:48 PM UTC+1, Marek Marczykowski-Górecki wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Fri, Feb 23, 2018 at 01:27:41PM -0800, Yuraeitha wrote: > > On Thursday, February 22, 2018 at 9:26:42 AM UTC+1, Elias Mårtenson wrote: > > > On 22 Feb 20

Re: [qubes-devel] network attach problem after the last updates on 3.2

2018-02-23 Thread M. Vefa Bicakci
On 02/23/2018 11:52 AM, Zrubi wrote: I have a strange problem after updating my system (3.2) from the testing repository. Changing the NetVM of a proxyVM, takes longer time than before, but succeed - at least according to Qubes manager (and qvm tools) But after the change, no traffic visible on

Re: [qubes-devel] Re: [qubes-announce] QSB #38: Qrexec policy bypass and possible information leak

2018-02-23 Thread bowabos
On Tuesday, 20 February 2018 13:04:15 UTC, Wojtek Porczyk wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Tue, Feb 20, 2018 at 01:21:30PM +0100, 'Tom Zander' via qubes-devel wrote: > > On Tuesday, 20 February 2018 01:49:37 CET Marek Marczykowski-Górecki wrote: > > > We've decide