Re: [qubes-users] Installing app on template when it requires signing?

2017-09-16 Thread Franz
On Sat, Sep 16, 2017 at 10:12 PM, Stumpy  wrote:

> I tried installing sonarr and it apparently requires that the repo be
> signed. I thought no problem until I tried:
>sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys
> FDA5DFFC
> and I got:
>   gpg: keyserver receive failed: No route to host
> I figure I should be able to download the key from appvm but am not sure
> how to do that as I tried the "sudo apt-ket" line from above and I guess it
> installed the key on the appvm instead of dl'd it, or perhaps it dl'd it
> but I don't know to where.
> Thoughts on how to get around this?
>
>
Try to open the firewall on template for 5 minute, there a flag on Qubes
Manager

>
> --
> You received this message because you are subscribed to the Google Groups
> "qubes-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to qubes-users+unsubscr...@googlegroups.com.
> To post to this group, send email to qubes-users@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/ms
> gid/qubes-users/d5ca1c2642219e5e2a858e260eeaca61%40posteo.net.
> For more options, visit https://groups.google.com/d/optout.
>

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAPzH-qCD1%2BNKoJyGu9G7zQ5OZmeZYymrC5yOwa%3DnnafDbE_VOQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Installing app on template when it requires signing?

2017-09-16 Thread Stumpy
I tried installing sonarr and it apparently requires that the repo be 
signed. I thought no problem until I tried:
   sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 
FDA5DFFC

and I got:
  gpg: keyserver receive failed: No route to host
I figure I should be able to download the key from appvm but am not sure 
how to do that as I tried the "sudo apt-ket" line from above and I guess 
it installed the key on the appvm instead of dl'd it, or perhaps it dl'd 
it but I don't know to where.

Thoughts on how to get around this?


--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/d5ca1c2642219e5e2a858e260eeaca61%40posteo.net.
For more options, visit https://groups.google.com/d/optout.


Fwd: Optimize Battery runtime with TLP for (Was [qubes-users] Lenovo X230 - List of USB-Ports and USB-Controllers (Layout))

2017-09-16 Thread 'P R' via qubes-users
Hello Taiidan,

Am 14.09.2017 7:33 vorm. schrieb "taii...@gmx.com" :

It is because of the VM overhead (close ones you don't need), you should
also set cpu powersave to "on demand" and force pci-e aspm.

In comparison I get around 5 hours of battery life with a 65Wh battery.


I have no installed TLP in dom0 via 'sudo qubes-dom0-update tlp tlp-rdw'.

Next step was to start TLP via 'sudo tlp start' and went straight into
battery mode. You can always switch via 'sudo tlp bat' or 'sudo tlp ac'.
As far as I know TLP will do so automatically.

I have switched of all App/Sys-VMs and if dom0 is running the x230 is using
~7.000 - 7.700 mW.
Battery runtime is now given with ~12-13 hours, which sounds unrealistic to
me and of course it doesn't make sense to run Qubes without any AppVM :-)

With some AppVMs running like:
sys-net / sys-firewall / sys-usb / Webbrowser AppVM, attached USB Mouse,
Wifi enabled and doing some Webbrowsing battery is now using ~11.000-13.500
mW.
Battery runtime is now estimated with 7 hours.

So it seems that TLP makes big difference when it installed.

I have installed it not only in dom0, but also my AppVM templates.

- P

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAM8xnvL-BAMvYK%3Ds-C73RfAzRXPm%2BN7K4P48bTeeFHA4kGz5Ag%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Can't access my luks secondary drive?

2017-09-16 Thread Stumpy
I have a secondary drive that is luks encrypted and can't seem to 
connect to it consistently.

Sometimes it doesn't show up at all
Other times in the vm manager it says its connected, but I can't see it, 
its not mounted in /mnt or /media

I also can't "find" it via the file manager

Here are two devices I see when I try to attach my drive:
Attach dom0: md127 0 B ()
Attach dom0: dm-8 1862 GiB luks-randome-strong-numbers

The second is the one I can't open (though, while I am at it, what is 
this "md 127 0 B ()"? It shows up even when I don't have other devices 
plugged in)


I am running 3.2 and am all up to date as far as I know (checked for 
updates for both of the templates RH24 and Db9)


--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/024b19cfae3ce216652859929bfc2bfe%40posteo.net.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Re: Qubes OS 4.0 without IOMMU

2017-09-16 Thread damm swing
On Friday, September 15, 2017 at 11:44:58 PM UTC+2, Marek Marczykowski-Górecki 
wrote:
> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA256
> 
> On Fri, Sep 15, 2017 at 08:58:22AM -0700, damm swing wrote:
> > On Friday, September 15, 2017 at 12:42:12 AM UTC+2, Damm Swing wrote:
> > > On Thursday, September 14, 2017 at 11:12:26 PM UTC+2, Yethal wrote:
> > > > W dniu czwartek, 14 września 2017 21:22:52 UTC+2 użytkownik damm swing 
> > > > napisał:
> > > > > Hello,
> > > > > 
> > > > > 
> > > > >  
> > > > > 
> > > > > 
> > > > > Will it be possible to use the final version of Qubes OS 4.0 (at your 
> > > > > own risk) on hardware without IOMMU (only with SLAT)?
> > > > > 
> > > > > 
> > > > >  
> > > > > 
> > > > > 
> > > > > Regards
> > > > 
> > > > PCI assignment won't work without IOMMU so no sys-net and no sys-usb
> > > 
> > > Is there no way to force PV mode in PCI VMs?
> > 
> > I found some sentence about that: "The new Core Stack allows one to do this 
> > with the flip of a switchproperty" 
> > https://www.qubes-os.org/news/2017/07/31/qubes-40-rc1/
> 
> Yes, it is possible to switch sys-net and sys-usb to PV, but even for PV
> IOMMU makes a great difference. See here:
> https://www.qubes-os.org/doc/user-faq/#can-i-install-qubes-on-a-system-without-vt-d
> 
> - -- 
> Best Regards,
> Marek Marczykowski-Górecki
> Invisible Things Lab
> A: Because it messes up the order in which people normally read text.
> Q: Why is top-posting such a bad thing?
> -BEGIN PGP SIGNATURE-
> Version: GnuPG v2
> 
> iQEcBAEBCAAGBQJZvEnSAAoJENuP0xzK19csQ4EH/1feU2j6eYUvRN0WBlwDtYdb
> 8PvF3Qk/nXuYRIzBjQ2ykHc6MsX4YQdvRU1gI90JdHX+5y6PSrKGGm8O5AWxhRp6
> Xl1Ev5Xs5vV8wCjcYp9FVpMmD+aGx06CtHaWkhQkMe7rhSxcoxASBZiMNvCl/kWC
> D4wZ2Hvg5Fp3LqiEHfx3Kei8OSqnd/UaVRnLcMSkQ4B64ilkJbT036AbNNYCN0wW
> saTSOxzEHzSrLvBvBm50n7v7f+jJCxnGPeeWxdW9dWXyXdAThTiKk/RtYp+0ZYv3
> /FNdvNhJ24kjF7KE1NffHGVoYY4veoGISfV/TSeQ86GIjxF98yaV0ji0UonRYIo=
> =aHth
> -END PGP SIGNATURE-

Thank you for your answer.
By the way, is it possible that some AppVM could compromise NetVM (e.g. by a 
hypothetical bug in Xen net backend) and then use the DMA attack?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/7f8d45cb-653a-4735-9307-b3d4ce54c101%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Re: Can't get disposable VMs to work

2017-09-16 Thread Selton
> You may try to update just xen packages (which is where the fix is):
> 
> sudo qubes-dom0-update --action=update 'xen*'

Okay, worked in that way that I'm still able to use qubes after the update and 
it eliminated the error line with the record truncated
>xc: error: X86_PV_VCPU_MSRS record truncated: length 8, min 9: Internal error

However, besides that my basic problem still persists in the exact same way. So 
I do get the same error from the screenshot above (exactly the same) when I try 
to start a dispVM and in the /var/log/libvirt/libxl/libxl-driver.log there are 
now the following 3 lines per try (instead of 4 before):
>xc: error: Restore failed (0 = Success): Internal error
>libxl: error: libxl_stream_read.c:749:libxl__xc_domain_restore_done: restoring 
>domain: Success
>libxl: error: libxl_create.c:1145:domcreate_rebuild_done: cannot (re-)build 
>domain: -3

I have tried deletion and recreation of the dispVM template several times as 
well as reboots. I also switched the dispVM template versions (fedora-23, 24 
and 25) but without luck.

I guess this is some progress but unfortunately dispVMs are still not working.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/6ac2cf28-5e89-4189-94f9-472d3eb06b45%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] R4.0-rc1 on T470: unable to boot (reboot loop)

2017-09-16 Thread rysiek
Hi all,

first of all, hello. Been meaning to sign up for this list for some time, some 
of you might remember me from the IRC channel (from when I was setting up my 
own Qubes devel builds).

Anywhoo. I decided to give R4.0-rc1 a spin on my Thinkpad T470, and after 
successfully going through the installation process, I am stuck at this issue:
https://groups.google.com/forum/#!topic/qubes-users/Pf1Cd87KSsk

Selecting any of the two options in GRUB ends up rebooting the device. Tried 
removing "quiet" from kernel options, nothing changed. Any suggestions on how 
can I get some debugging output?

QubesOS R3.2 does not run on T470s at all (old kernel vs. new hardware; new 
hardware clearly wins).

Thanks!

-- 
Pozdrawiam,
Michał "rysiek" Woźniak

Zmieniam klucz GPG :: http://rys.io/pl/147
GPG Key Transition :: http://rys.io/en/147

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/2493743.SxXS9MZMd7%40lapuntu.
For more options, visit https://groups.google.com/d/optout.


signature.asc
Description: This is a digitally signed message part.


Re: [qubes-users] Acer Aspire E 15

2017-09-16 Thread Feral-Fractals7
Okay thank you for the information. 

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/011c78d5-9235-44cc-abf4-61ab7d1c903e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: [3.2] Issues with Intel® HD Graphics 620 after update of clean installation

2017-09-16 Thread mirek . wojciechowski
W dniu czwartek, 4 maja 2017 19:16:33 UTC+2 użytkownik Vít Šesták napisał:
> I have installed Qubes OS on a new laptop. Immediately after installing, I 
> decided to run qubes-dom0-update and then also qubes-dom0-update 
> --enablerepo=qubes-dom0-security-testing in order to patch recent Xen 
> vulnerabilities.
> 
> Before reboot, Qubes worked smoothly. After reboot, the GUI is quite lazy – 
> mouse movement is slooow, typing lag is high (so I prefer tty over xfce
> -terminal for performance reasons) etc. I haven't measured the lag exactly, 
> but it can be about 1s.
> 
> So, I have looked at /var/log/Xorg.0.log. There are few errors, the first one 
> seems to be the root cause:
> 
> open /dev/dri/card0: No such file or directory
> 
> (I have retyped it, because it would be painful to copy it.)
> 
> Others are about GPU fallbacks and also “AIGLX: reverting to software 
> rendering”.
> 
> So, my reconstruction is that /dev/dri does not exist and thus it to use HW 
> acceleration and thus it is so slow. It makes sense, except that I don't know 
> why /dev/dri is missing. It is reportedly created by kernel, so I assume it 
> is related to i915 module and/or newer kernel version.
> 
> When I run lsmod | grep i915, it shows it is loaded. But it is apparently not 
> used, because I can rmmod it. I have tried to reinstall GPU drivers package, 
> but it did not help.
> 
> My other idea was to boot Qubes with the old kernel. But I don't know how to 
> do it with UEFI boot. With Legacy boot, there is a Grub menu where I can 
> choose an old kernel, edit kernel cmdline etc. With UEFI boot, I can see 
> nothing like it. Just when I press F12 in early boot stage, I can select what 
> to boot, but I can select just Qubes here, without any options.
> 
> What to do now?
> 
> Configuration:
> 
> * Dell Inspiron 15Z Touch 5578
> * Intel i7-7500U CPU
> * No dedicated GPU (I hoped to have less issues when I have just the 
> integrated one…)
> * UEFI boot.
> 
> Regards,
> Vít Šesták 'v6ak'

On my unstable kernel: 4.9.35-19, i had the same problem on my Lenovo T470p, 
what did i do that works well?

I have removed the kernel option: nomodeset

Now, /boot/efi/EFI/qubes/xen.cfg looks like this:

-
[global]
default=4.9.35-19.pvops.qubes.x86_64

[4.9.35-19.pvops.qubes.x86_64]
options=loglvl=all dom0_mem=min:1024M dom0_mem=max:4096M
kernel=vmlinuz-4.9.35-19.pvops.qubes.x86_64 root=/dev/mapper/qubes_dom0-00 
rd.luks.uuid=luks-06c35d45-4a71-4b89-973b-ef8f8aebc2a8 rd.lvm.lv=qubes_dom0/00 
rd.lvm.lv=qubes_dom0/swap rhgb quiet
ramdisk=initramfs-4.9.35-19.pvops.qubes.x86_64.img

[4.9.35-19.pvops.qubes.x86_64]
options=loglvl=all dom0_mem=min:1024M dom0_mem=max:4096M
kernel=vmlinuz-4.9.35-19.pvops.qubes.x86_64 root=/dev/mapper/qubes_dom0-00 
rd.luks.uuid=luks-06c35d45-4a71-4b89-973b-ef8f8aebc2a8 rd.lvm.lv=qubes_dom0/00 
rd.lvm.lv=qubes_dom0/swap rhgb quiet
ramdisk=initramfs-4.9.35-19.pvops.qubes.x86_64.img
-

Regards

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/d5d22b8d-c838-4f87-a466-2898fc12ba8c%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: off topic - invite codes to 'riseup'

2017-09-16 Thread stephen . liss
On Tuesday, October 28, 2014 at 11:26:49 AM UTC-7, 
bm-2cu9wcijafoqtf6...@bitmessage.ch wrote:
> Dear qubes-users,
> 
> I am long time qubes follower and user. I apologize in advance if anyone 
> feels this request is spam.
> 
> I am looking for two invite codes needed to sign up to anonymous 
> riseup.net email service.
> 
> I am hoping there are some qubes users who are riseup.net account 
> holders.
> 
> Can anyone please send me a couple of invite codes that I might be able 
> to sign up?
> 
> Thank you in advance.

I too could use an invite code, please & thanks. 

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/03211b34-27a7-4079-ba78-c15fde99a94c%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.