Re: [qubes-users] Updates Proxy a security Risk?

2016-08-13 Thread Marek Marczykowski-Górecki
e mirrors etc), that assuming none of it can be compromised is unrealistic. On the other hand, even compromised mirror can't do anything about properly signed package (besides hiding its existence). Updates proxy is only to prevent user mistakes - like browsing the web directly from the templa

Re: [qubes-users] USB keyboard with trackpad and trackpoint recognized as mouse

2016-08-13 Thread Marek Marczykowski-Górecki
get it recognized as a keyboard + mouse? Take a look here: https://www.qubes-os.org/doc/usb/#tocAnchor-1-1-4 - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -B

Re: [qubes-users] grub2-mkconfig not found

2016-08-13 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Aug 13, 2016 at 06:53:20AM -0700, zackp...@gmail.com wrote: > On Saturday, August 13, 2016 at 6:14:44 AM UTC-4, Marek Marczykowski-Górecki > wrote: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > &

Re: [qubes-users] Qubes 3.1 - Fedora update check disabled but still check

2016-08-13 Thread Marek Marczykowski-Górecki
tes - in case of template-based VM, those will be updates for its template. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Ve

Re: [qubes-users] Manual https://www.qubes-os.org/doc/templates/archlinux/ does not work.

2016-08-13 Thread Marek Marczykowski-Górecki
] Error 1 > > Makefile:188: recipe for target 'vmm-xen.get-sources-extra' failed > > make: *** [vmm-xen.get-sources-extra] Error 2 > > > Hi, again. Here is full log. "Step 9" meaning install 'make qubes-vm' > command :) > > [root@

Re: [qubes-users] Unable to install R3.1 / media check failure

2016-08-13 Thread Marek Marczykowski-Górecki
n new release. Unless Windows create the other file ("WPSettings.dat")... - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Versi

Re: [qubes-users] Query on upgrade process - what next after downloading the fedora23 template?

2016-08-16 Thread Marek Marczykowski-Górecki
and which is preferable depends on things > like the modifications (if any) you've made to your template(s) and how > acceptable you find the results of the in-place upgrade procedure for your > individual purposes. I'm not sure if I understand the intention here, bu

Re: [qubes-users] Qubes 3.2-rc2 very high hard disk activity

2016-08-16 Thread Marek Marczykowski-Górecki
m it has just under 200M in RES column, but you probably have even less). Also check swap usage in VMs - maybe its about some VM, not dom0? - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-

Re: [qubes-users] Re: Windows7 issue with Dom0 GUI Daemon

2016-08-16 Thread Marek Marczykowski-Górecki
gt; > If you're logged into GitHub, there should be a "reopen" button (not sure if > visibility is permissions-based). You should probably test the patch that is > supposed to fix the issue before reopening it, though. The patch should be > available for testing soon. The updated

Re: [qubes-users] Network Access dom0

2016-08-17 Thread Marek Marczykowski-Górecki
ial exceptions I need to > >>>>>>>> add to the sys-firewall vm? > >>>>>>>> > >>>>> > >>>>> Are you downloading updates via Tor (sys-whonix)? If so, > >>>>> try requesting a new identity (press

Re: [qubes-users] networking issues

2016-08-18 Thread Marek Marczykowski-Górecki
maintain later. [1] https://www.qubes-os.org/doc/managing-vm-kernel/#tocAnchor-1-1-3 - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP

Re: [qubes-users] Routing network traffic in sys-usb using multiple devices

2016-08-18 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Aug 18, 2016 at 08:25:34AM -0700, Adrian Rocha wrote: > El viernes, 12 de agosto de 2016, 2:34:52 (UTC-6), Marek Marczykowski-Górecki > escribió: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > >

Re: [qubes-users] Routing network traffic in sys-usb using multiple devices

2016-08-18 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Aug 18, 2016 at 09:12:35AM -0700, Adrian Rocha wrote: > El jueves, 18 de agosto de 2016, 9:45:44 (UTC-6), Marek Marczykowski-Górecki > escribió: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > >

Re: [qubes-users] Boot problems on Lenovo T420 thinkpad

2016-08-29 Thread Marek Marczykowski-Górecki
ere > to find it. Googling hasn't helped me so far, and I'd really appreciate > any help you all could provide. > > Thanks so much for all your work!! Looking forward to getting Qubes going. One of easiest way is `df /boot/efi` command - you'll see something like /dev/sda1 at

Re: [qubes-users] qvm-run only available from dom0?

2016-08-29 Thread Marek Marczykowski-Górecki
ly to Disposable VM (DispVM in short), which by design should start from clean state. > If I'm very careful about the permissions, I should be able to keep any > risk under control. The qrexec design looks pretty flexible. > > Thanks! > - -- Best Regards, Marek Marczy

Re: [qubes-users] Qubes OS installation freezes at installing bootloader?!

2016-08-29 Thread Marek Marczykowski-Górecki
; the moment where installer says "installing bootloader". Every time! > > If anyone have some solution to this, please share! UEFI or legacy mode? In any case, try the other one. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order

Re: [qubes-users] grub2-mkconfig not found

2016-08-29 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Aug 14, 2016 at 06:14:12PM -0700, zackp...@gmail.com wrote: > On Saturday, August 13, 2016 at 5:45:58 PM UTC-4, Marek Marczykowski-Górecki > wrote: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > &

Re: [qubes-users] Routing network traffic in sys-usb using multiple devices

2016-08-29 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Aug 18, 2016 at 10:34:55AM -0700, Adrian Rocha wrote: > El jueves, 18 de agosto de 2016, 10:50:14 (UTC-6), Marek Marczykowski-Górecki > escribió: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > >

Re: [qubes-users] Template Updates through http proxy

2016-08-29 Thread Marek Marczykowski-Górecki
it in the template (by default fedora-23), or apply the modification from /rw/config/rc.local in particular VM (sys-net). If you choose to use rc.local, make it executable. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people nor

Re: [qubes-users] Anonymizing MAC adress through dvm ?

2016-08-29 Thread Marek Marczykowski-Górecki
ives information that you use Qubes OS. And if one can read that MAC address, can also read a dozen other indicators that you use Qubes OS - like running on Xen, or /var/lib/qubes directory presence, or simply a hostname ("dispXX"). - -- Best Regards, Marek Marczykowski-Górecki Inv

Re: [qubes-users] Isn't it bad, that compromized vm can create any number of dispVMs?

2016-08-29 Thread Marek Marczykowski-Górecki
ited - by available RAM. Further attempts will simply fail. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Version:

Re: [qubes-users] Re: Unable to install 3.2-rc1 on Thinkpad T450s

2016-08-29 Thread Marek Marczykowski-Górecki
ade and it wouldn't even boot off USB. > > > > So I pulled the drive, put it in another laptop (Samsung ATIV book 9 plus) > > and 3.2 installed and worked. I updated everything, put the drive back in > > the x260 and boot borked. > > Adding: > mapbs=1 > no

Re: [qubes-users] Salt InterVM Configuration explorations and pitfalls in 3.2-rc2

2016-08-29 Thread Marek Marczykowski-Górecki
ings - almost all Xfce configuration is in XML files... > > The best would be augeas.change state which uses augeas which can make > modifying structured data type files a one line thing. Thanks, will take a look at it! > It would be perfect for this but has some dependen

Re: SOLVED --- Re: [qubes-users] Re: qvm-usb does not detect all devices, crashes

2016-08-30 Thread Marek Marczykowski-Górecki
uishable from other Dell devices. If device lack of textual information about the device, you always see numeric representation, which you can correlate with lsusb output. You can easily get it in dom0 using: qvm-run -p sys-usb lsusb. If you have a better idea for device description, please share proposi

Re: [qubes-users] Weird network access issues

2016-08-30 Thread Marek Marczykowski-Górecki
VMs are not connecting to anything > outside Qubes anymore. the only VM that was connecting was sys-firewall. > The next time it happens I will write down what exactly I am > experiencing and if the connection between the VMs are working properly. Wasn't that after starting some AppVM by a c

Re: [qubes-users] R3.1 - "Freezing?" sys-usb VM via mkfs.vat command

2016-08-30 Thread Marek Marczykowski-Górecki
you have no other VMs running, it will not use free memory. This is mostly requirement to handle PCI devices, which require continuous memory region. But you can increase this assignment in sys-usb settings. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it m

Re: [qubes-users] Q3.2 rc2 Restore from buckup error

2016-08-30 Thread Marek Marczykowski-Górecki
re dialog (or add - --ignore-missing if you're using command line tool). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Ve

Re: [qubes-users] Salt InterVM Configuration explorations and pitfalls in 3.2-rc2

2016-08-30 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Aug 29, 2016 at 11:07:33PM -0700, nekroze.law...@gmail.com wrote: > On Tuesday, August 30, 2016 at 12:20:32 PM UTC+10, Marek Marczykowski-Górecki > wrote: > > > > > fedora-23-minimal templates are unmanageable

Re: [qubes-users] Salt InterVM Configuration explorations and pitfalls in 3.2-rc2

2016-08-31 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Aug 30, 2016 at 11:00:30PM +0200, Marek Marczykowski-Górecki wrote: > On Mon, Aug 29, 2016 at 11:07:33PM -0700, nekroze.law...@gmail.com wrote: > > Also, I am not sure when, but the pkg.uptodate state does nothing in > > te

[qubes-users] Qubes 3.2 rc3 has been released!

2016-08-31 Thread Marek Marczykowski-Górecki
. For older releases check above page for upgrade instructions. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Version: GnuPG v2

Re: [qubes-users] Qubes 3.2 rc3 has been released!

2016-08-31 Thread Marek Marczykowski-Górecki
tions. > > Congrats on another milestone. > > For those of us tracking testing, we're automatically swept along with our > updates (just as users of rc1/rc2), correct? If you're using 3.1 or older (with testing repos enabled or not), you need to go through upgrade procedure

Re: [qubes-users] Salt InterVM Configuration explorations and pitfalls in 3.2-rc2

2016-08-31 Thread Marek Marczykowski-Górecki
e such as tinyproxy requires? Take a look at grains - there is a standard `ipv4` available. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE

Re: [qubes-users] Re: epoxy on ram to prevent cold boot attacks?

2016-08-31 Thread Marek Marczykowski-Górecki
vulnerable for bug in USB stack itself, but the attack surface is much, much smaller than all the USB devices drivers (some unmanaged for years). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-po

Re: [qubes-users] Re: epoxy on ram to prevent cold boot attacks?

2016-09-01 Thread Marek Marczykowski-Górecki
reject any non-keyboard device > > before allowing any driver to talk to it. This will still left you > > vulnerable for bug in USB stack itself, but the attack surface is much, > > much smaller than all the USB devices drivers (some unmanaged for > > years). > > Ver

Re: [qubes-users] Broken applications menu/shortcuts with xfce

2016-09-02 Thread Marek Marczykowski-Górecki
elcome. Check to what command those .desktop files points - should have something like Exec=qvm-run Try to call that exact command manually and see if you'll get some error. If not (but still application do not launch), add "-p" option to get more details. - -- Best Regards, M

Re: [qubes-users] Announcement: Qubes OS 3.0 reaches EOL on 2016-09-09

2016-09-03 Thread Marek Marczykowski-Górecki
e before 2016-09-09" really recommending the 3.2 release > candidate? Unless some major bug will be found in R3.2-rc3 (which is unlikely), the final R3.2 will be exactly the same as R3.2-rc3. So, yes - upgrading to R3.2-rc3 seems as a reasonable step. - -- Best Regards, Marek Marczykowski-

Re: [qubes-users] R3.2 USB passthough Windows HVM

2016-09-03 Thread Marek Marczykowski-Górecki
art is connecting those two together. As for passing through the whole USB controller, it is broken currently: https://github.com/QubesOS/qubes-issues/issues/1659 We'll work on this some more this month and hopefully fix it. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Be

Re: [qubes-users] 3.2-rc1, xfce4 volume control

2016-09-04 Thread Marek Marczykowski-Górecki
n mixer app - middle-click on mixer applet is enough. I think it may not be Qubes specific bug at all, but haven't looked if upstream report for it exists. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read tex

Re: [qubes-users] Qubes 3.1 and 3.2 beta both fail in post-install configuration

2016-09-04 Thread Marek Marczykowski-Górecki
r configuration to load Linux directly, excluding Xen. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAA

Re: [qubes-users] xdg and /etc/qubes/autostart

2016-09-05 Thread Marek Marczykowski-Górecki
there should be README.txt. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJXzThEAAoJENuP0xzK19csNH

Re: [qubes-users] xdg and /etc/qubes/autostart

2016-09-05 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Sep 05, 2016 at 11:26:03AM +0200, Achim Patzner wrote: > Am 05.09.2016 um 11:17 schrieb Marek Marczykowski-Górecki: > > On Mon, Sep 05, 2016 at 10:31:17AM +0200, Achim Patzner wrote: > > > Is there any documentation

Re: [qubes-users] Qubes 3.1 and 3.2 beta both fail in post-install configuration

2016-09-05 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Sep 05, 2016 at 02:57:13AM -0700, Bob Newell wrote: > On Sunday, September 4, 2016 at 2:45:03 PM UTC-4, Marek Marczykowski-Górecki > wrote: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > > On S

Re: [qubes-users] Changing default user from "user" to something else in AppVMs

2016-09-05 Thread Marek Marczykowski-Górecki
lse than logged in user. You can also try changing $USER and/or $LOGNAME environment variables. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGN

Re: [qubes-users] yubikey challenge-response

2016-09-05 Thread Marek Marczykowski-Górecki
iet > /usr/local/bin/yubikey-auth 04c21478245c36861b9f946e0d9388d5ebbb909d > d0be2dc421be4fcd0172e5afceea3970e2f3d940 Do you have anything in logs in dom0 (check `sudo journalctl -eb`)? Do you have ykchalresp installed in template of sys-usb? It's part of ykpers package. - --

Request for test: Re: [qubes-users] Fedora 24?

2016-09-05 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Jun 23, 2016 at 09:31:46PM +0200, Niels Kobschaetzki wrote: > On 16/06/23 00:28, Marek Marczykowski-Górecki wrote: > > On Wed, Jun 22, 2016 at 11:41:12AM +0200, Niels Kobschätzki wrote: > > > Hi, > > > >

Re: Request for test: Re: [qubes-users] Fedora 24?

2016-09-06 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Sep 06, 2016 at 12:24:54AM -0700, Foppe de Haan wrote: > On Tuesday, September 6, 2016 at 1:24:09 AM UTC+2, Marek Marczykowski-Górecki > wrote: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > >

Re: Request for test: Re: [qubes-users] Fedora 24?

2016-09-06 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Sep 06, 2016 at 08:27:09AM +0200, Achim Patzner wrote: > Am 06.09.2016 um 01:24 schrieb Marek Marczykowski-Górecki: > > I've just tried this and successfully upgraded Fedora 23 to Fedora 24 > > template. > > >

Re: [qubes-users] OpenBSD Xen PHVM

2016-09-06 Thread Marek Marczykowski-Górecki
know if that's all what is required. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJXzp+GAAo

Re: Request for test: Re: [qubes-users] Fedora 24?

2016-09-06 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Sep 06, 2016 at 01:07:49PM +0200, Achim Patzner wrote: > Am 06.09.2016 um 11:30 schrieb Marek Marczykowski-Górecki: > > There are no fc24 packages for R3.1. So if you're starting with R3.1 > > template, first you need t

Re: Request for test: Re: [qubes-users] Fedora 24?

2016-09-06 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Sep 06, 2016 at 01:10:51PM +0200, Achim Patzner wrote: > Am 06.09.2016 um 11:17 schrieb Marek Marczykowski-Górecki: > > Just some standard usage things, like: > > - networking (like standard web browsing) > > Worki

Re: [qubes-users] Re: OpenBSD Xen PHVM

2016-09-06 Thread Marek Marczykowski-Górecki
part missing (in addition to my previous email): network backend driver. Without this, it is impossible to have ProxyVM. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thin

Re: [qubes-users] Did 3.0 -> 3.1 proceed correctly?

2016-09-06 Thread Marek Marczykowski-Górecki
ug in upgrade instruction). Also qubes-mgmt-salt-vm-connector package is needed in default template to manage in-VM configuration. > * Command `yum list` never shows 3.0.* for Qubes packages, with few > exceptions for templates and Windows tools. > > It this result correct? Bes

Re: [qubes-users] Feedback and errors on installation

2016-09-06 Thread Marek Marczykowski-Górecki
chainloader /EFI/BOOT/xen.efi boot Take a look at grub configuration on installation image (/EFI/BOOT/grub2.cfg). Also take a look here for troubleshooting UEFI related problems: https://www.qubes-os.org/doc/uefi-troubleshooting/ - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A:

Re: [qubes-users] Feedback and errors on installation

2016-09-06 Thread Marek Marczykowski-Górecki
otmgr. Some hints here: https://www.qubes-os.org/doc/uefi-troubleshooting/ (especially step 8 have a line to add boot entry). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a b

Re: [qubes-users] yubikey challenge-response

2016-09-06 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Sep 06, 2016 at 12:34:49PM -0700, Peter Ihasz wrote: > 2016. szeptember 6., kedd 18:39:58 UTC+1 időpontban Peter Ihasz a következőt > írta: > > 2016. szeptember 5., hétfő 21:09:33 UTC+1 időpontban Marek > > Marc

Re: [qubes-users] Feedback and errors on installation

2016-09-06 Thread Marek Marczykowski-Górecki
t; ^^ > > I would like to re-install grub on /dev/sda but in dom0 , there is no grub > binaries > I also have to see how I can install / update the system Yes, in EFI mode grub is not used in installed system at all. But if you want, you can install it with "qubes-dom0-update

Re: Request for test: Re: [qubes-users] Fedora 24?

2016-09-07 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Sep 06, 2016 at 08:44:35PM -0700, pixel fairy wrote: > > On 09/05/2016 08:24 PM, Marek Marczykowski-Górecki wrote: > > > Please, if any of you have a chance, test such template. > > Whats the time frame on 3.2? fedora

Re: [qubes-users] Feedback and errors on installation

2016-09-08 Thread Marek Marczykowski-Górecki
switch in BIOS to legacy mode only). And please, do not top post! - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Version: GnuPG v2

[qubes-users] Qubes Security Bulletin #25

2016-09-08 Thread Marek Marczykowski-Górecki
. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJX0VS0AAoJENuP0xzK19csgkcH/R0z5UXeQ6agHKWmUNNuSCVe

Re: [qubes-users] Current Windows instructions?

2016-09-11 Thread Marek Marczykowski-Górecki
ct R3.1 to get any new > >> features but if QWT3.2 is improving stability, it'd be great to > >> get it if possible. > > > > > > That's a good question. I can confirm what you're seeing (in terms > > of what's available in the Qubes repos),

Re: [qubes-users] USB controller after resume

2016-09-11 Thread Marek Marczykowski-Górecki
> it. In fact those modules (besides USBIP) should be blacklisted by default. Take a look at /etc/qubes-suspend-module-blacklist. Maybe it doesn't work for some reason? Or the file wasn't updated (and the new on is in .rpmnew)? - -- Best Regards, Marek Marczykowski-Górecki Invisi

Re: [qubes-users] USB controller after resume

2016-09-11 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Sep 11, 2016 at 12:41:31PM -0700, Vít Šesták wrote: > On Sunday, September 11, 2016 at 8:52:36 PM UTC+2, Marek Marczykowski-Górecki > wrote: > > In fact those modules (besides USBIP) should be blacklisted by default. > > T

Re: [qubes-users] USB controller after resume

2016-09-11 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Sep 11, 2016 at 01:12:12PM -0700, Vít Šesták wrote: > On Sunday, September 11, 2016 at 9:54:42 PM UTC+2, Marek Marczykowski-Górecki > wrote: > > AFAIR only *_pci modules are talking to the hardware, so removing them > >

Re: [qubes-users] USB controller after resume

2016-09-11 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Sep 11, 2016 at 02:00:15PM -0700, Vít Šesták wrote: > On Sunday, September 11, 2016 at 10:15:52 PM UTC+2, Marek > Marczykowski-Górecki wrote: > > > However, after renaming the /rw/config/suspend-module-blacklist, > >

Re: [qubes-users] USB controller after resume

2016-09-11 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Sep 11, 2016 at 02:25:29PM -0700, Vít Šesták wrote: > On Sunday, September 11, 2016 at 11:13:51 PM UTC+2, Marek > Marczykowski-Górecki wrote: > > Interesting. Any errors in journalctl? > > Nothing interesting found there.

Re: [qubes-users] trackpad driver on Librem 13

2016-09-11 Thread Marek Marczykowski-Górecki
s version preinstalled by Purism, it should be there, but if you have installed it yourself, you need to update the dom0 kernel. Applying updates normally (`sudo qubes-dom0-update`) should be enough. You need version 4.1.24-10 or later. - -- Best Regards, Marek Marczykowski-Górecki Invisible Th

Re: [qubes-users] cloning sys-net

2016-09-12 Thread Marek Marczykowski-Górecki
that copy command with an "if [-f" Can you check if that icon is really missing, or rather it is there, but as a broken symlink? - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q:

Re: [qubes-users] 4.0 ETA?

2016-09-12 Thread Marek Marczykowski-Górecki
practice some more. As for upgrade - currently we don't plan to support in-place upgrade from 3.x to 4.0. But as usual, it will be possible to migrate using backup & restore. [1] https://www.qubes-os.org/doc/version-scheme/#tocAnchor-1-1-3 - -- Best Regards, Marek Marczykowski-Górecki Invis

Re: [qubes-users] Using virt-viewer for remote systems

2016-09-12 Thread Marek Marczykowski-Górecki
ibs package: Fedora 23 have 4.5, but Qubes 3.1/3.2 use 4.6. And all the Qubes related packages are linked with 4.6, while Fedora ones with 4.5. Try upgrading to Fedora 24, which uses Xen 4.6. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in wh

Re: [qubes-users] 4.0 ETA?

2016-09-13 Thread Marek Marczykowski-Górecki
(for example Disposable VMs most likely will not). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Version: GnuPG

Re: [qubes-users] multiple display support

2016-09-13 Thread Marek Marczykowski-Górecki
-hotplug.conf Section "Device" Identifier "intel" Driver "intel" Option "HotPlug" "false" EndSection It helps somehow, but still will detect that external display gets disconnected when explicitly asked (`xrandr`). With all its consequenc

Re: [qubes-users] Re: Qubes OS 3.2 rc3: can not boot with VT-d enabled on DELL T7400 (XEON E5440, Intel 5400 chipset)

2016-09-13 Thread Marek Marczykowski-Górecki
> Thanks, > > > > > > Ludwig > > I want to clarify: with VT-d disabled, the machine behaves and runs, but it > is > impossible to assign pci devices to VMs, because this is what VT-d is for. > With VT-d enabled, it chrashes after loading initrd.img Remove also &q

Re: [qubes-users] Re: Qubes 3.2-rc3 RAID and nvme

2016-09-13 Thread Marek Marczykowski-Górecki
n by "EFI won't boot"? Does it crash/hang during startup, or isn't detected at all? Take a look here: https://www.qubes-os.org/doc/uefi-troubleshooting/ Also take a look at those threads: https://groups.google.com/forum/#!topic/qubes-users/8Ui1csb2S9Q https://groups.google.com/d/to

Re: [qubes-users] multiple display support

2016-09-13 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Sep 13, 2016 at 10:19:32AM +0200, Zrubi wrote: > On 09/13/2016 10:02 AM, Marek Marczykowski-Górecki wrote: > > >> * panel are not sticked to my internal (primary) display. Both > >> KDE and XFCE behaving this way. M

Re: [qubes-users] Re: Qubes OS 3.2 rc3: can not boot with VT-d enabled on DELL T7400 (XEON E5440, Intel 5400 chipset)

2016-09-13 Thread Marek Marczykowski-Górecki
ort, but it require some additional hardware. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQEcBAEBCAAGBQJX

Re: [qubes-users] Re: Can DMA attacks work against Ethernet... or just WiFi/wireless...?

2016-09-13 Thread Marek Marczykowski-Górecki
s free to modify any network payload, > which is powerful as well; but short of that, can it actually compromise a > system or a VM?) > > JJ > - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people norma

Re: [qubes-users] Re: Can DMA attacks work against Ethernet... or just WiFi/wireless...?

2016-09-13 Thread Marek Marczykowski-Górecki
se Qubes. > > VT-d can do memory insulation, and should assign a memory range (pci-address > space of a pci device) exclusively to one VM, so the attacker of that hw can > do DMA into that VM, if done properly. > But there is that evil ME in the Northbridge. How does the ME-proc

Re: [qubes-users] installing Signal on Qubes mini-HOWTO

2016-09-14 Thread Marek Marczykowski-Górecki
reated by starting the fedora-23 template VM and then > running in a dom0 terminal: qvm-sync-appmenus fedora-23 > > 7. You should now be able to go back to the GUI and from the Q menu: Q -> > Domain: Signal -> Signal: Add more shortcuts... > In the window that will appear, y

Re: [qubes-users] Re: 4.0 ETA?

2016-09-14 Thread Marek Marczykowski-Górecki
se security[1], not a technical requirement of some software component. But this decision means that Qubes-specific component will no longer support non-compatible systems. [1] https://www.qubes-os.org/news/2016/07/21/new-hw-certification-for-q4/ - -- Best Regards, Marek Marczykowski-Górecki Invisi

[qubes-users] [qubes-announce] QSB-100: Incorrect handling of PCI devices with phantom functions (XSA-449)

2024-01-30 Thread Marek Marczykowski-Górecki
n/QSBs/qsb-100-2024.txt> ## [Marek Marczykowski-Górecki](https://www.qubes-os.org/team/#marek-marczykowski-górecki)'s PGP signature ``` - -BEGIN PGP SIGNATURE- iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmW5Di0ACgkQ1lWk8hgw 4GphzQ//Ta+g8Y7Cjmx0w+byISlTHoxao

Re: [qubes-users] 80x24 geometry used by qvm-console-dispvm

2024-03-06 Thread Marek Marczykowski-Górecki
" example > in https://qubes-os.org/support/ but it was rejected. Quite confusing. You must subscribe to qubes-devel mailing list to post there. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywF

Re: [qubes-users] 80x24 geometry used by qvm-console-dispvm

2024-03-06 Thread Marek Marczykowski-Górecki
o make automatic. If anybody has some idea, patches welcome. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAmXo5NcACgkQ24/THMrX 1yys0Qf6AmYB8Z7OIahL8zabnZ+RZkGc+YmJNcAnxeayFDBBkbOXjuNqKUSvCJ8w 1sKGOi

Re: [qubes-users] 80x24 geometry used by qvm-console-dispvm

2024-03-06 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, Mar 06, 2024 at 06:16:03PM -0500, Demi Marie Obenour wrote: > On Wed, Mar 06, 2024 at 10:49:11PM +0100, Marek Marczykowski-Górecki wrote: > > On Wed, Mar 06, 2024 at 06:13:50PM +0100, Ulrich Windl wrote: > > > Haven'

[qubes-users] Re: [qubes-devel] qvm-create-windows-qube Automatically creates

2019-08-20 Thread Marek Marczykowski-Górecki
sue and > I'll look into it. I haven't looked into details nor tried it yet, but on the first sight looks really cool! - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: W

Re: [qubes-users] Moving Qubes+VMs to Larger SSD - How to Handle Storage Pools on Other Disks?

2019-09-08 Thread Marek Marczykowski-Górecki
have the other part finished this week. In the meantime, you can try some naive methods of slowing down the extraction process, for example by attaching strace to it (`strace -p $(pidof qfile-dom0-unpacker)`), or pausing it from time to time by sending SIGSTOP signal (and then SIGCONT

[qubes-users] QSB #51: Insufficient validation of backup compression filter on restore

2019-09-10 Thread Marek Marczykowski-Górecki
ise-recovery/ [3] https://www.qubes-os.org/doc/backup-restore/ [4] https://www.qubes-os.org/doc/backup-emergency-restore-v4/ [5] https://www.qubes-os.org/doc/backup-emergency-restore-v3/ [6] https://www.qubes-os.org/doc/backup-emergency-restore-v2/ - -- The Qubes Security Team https://www.qubes-os

Re: [qubes-users] Safe to switch default-mgmt-dvm TemplateVM from Fedora 29 to Fedora 30?

2019-10-16 Thread Marek Marczykowski-Górecki
> Fedora 29). > > Should I just switch or rather not touch it? Yes, it's ok to and even desirable to switch. It should be based on stock template without less trusted repositories and software installed. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because i

[qubes-users] QSB #52: Xen issues affecting PCI passthrough and PV domains (XSA-299, XSA-302)

2019-10-31 Thread Marek Marczykowski-Górecki
.xen.org/xsa/advisory-299.html [2] https://xenbits.xen.org/xsa/advisory-302.html - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people norm

Re: [qubes-users] 2 new Intel vulnerabilites

2019-11-15 Thread Marek Marczykowski-Górecki
es-issues/issues/4855 - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl3PEHUACgkQ2

[qubes-users] QSB #55: Issues with PV type change and handling IOMMU on AMD (XSA-310, XSA-311)

2019-12-11 Thread Marek Marczykowski-Górecki
en.org/xsa/advisory-310.html [2] https://xenbits.xen.org/xsa/advisory-311.html - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is t

[qubes-users] QSB #56: Insufficient anti-spoofing firewall rules

2019-12-25 Thread Marek Marczykowski-Górecki
s-os.org/doc/firewall/#enabling-networking-between-two-qubes [2] https://nvd.nist.gov/vuln/detail/CVE-2019-14899 - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people no

Re: [qubes-users] Re: Qubes OS 4.0.2 has been released!

2020-01-09 Thread Marek Marczykowski-Górecki
safe to continue using it. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl4X0IEACgkQ24/THMrX

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-08 Thread Marek Marczykowski-Górecki
finding what exactly is changing (and preferably also why). And only then find how to mitigate this issue. If specific flags would turn out to be not related to security features or otherwise having unwanted effects, then ignoring those changes would be an option. But ignoring _only those flags verified t

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread Marek Marczykowski-Górecki
is AMD-only, > apparently. Unclear to me if the other items 1.2.35 and higher, which is > for "x86" apply only to intel or to all x86 architecture. I may be missing it in this thread, but have anybody tried Qubes 4.1 builds (with Xen 4.13) on such system? Does it have the same is

Re: [qubes-users] Is Qubes Split GPG safe?

2020-02-14 Thread Marek Marczykowski-Górecki
support in Thunderbird out of the box without requiring an addon - meaning probably more people will use it. BTW we need to verify is this major breakage of Thunderbird addons won't break other Qubes features too - namely opening attachments in DisposableVM, which is also done using an addon.

Re: [qubes-users] Another Intel vulnerability

2020-03-12 Thread Marek Marczykowski-Górecki
0) to attack Qubes, as relevant interfaces are not available from within a VM. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -B

Re: [qubes-users] Re: [4.0] Intel Wi-Fi 6 AX200 adapter

2020-03-19 Thread Marek Marczykowski-Górecki
not boot at all because of issues with >> attaching ethernet PCI device. Is it a Realtek card? I don't remember exactly what helped, but something helped here. Paweł, can you help? It was either attaching SD card reader (which is another function on the same PCI device) to the sys-net,

Re: [qubes-users] Re: [4.0] Intel Wi-Fi 6 AX200 adapter

2020-03-19 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Mar 20, 2020 at 01:05:02AM +0100, Vít Šesták wrote: > Hello, > > On March 20, 2020 12:33:31 AM GMT+01:00, "Marek Marczykowski-Górecki" > wrote: > >I didn't spot VT-d errors, but I'm not entirely sure

Re: [qubes-users] Qubes Updater doesn't update

2020-03-21 Thread Marek Marczykowski-Górecki
ository, and will be uploaded to current (aka stable) in few days. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEB

Re: [EXT] Re: [qubes-users] Qubes Updater doesn't update

2020-03-27 Thread Marek Marczykowski-Górecki
On Sat, Mar 28, 2020 at 12:57:55AM +0100, Ulrich Windl wrote: > On 2020-03-21 20:39, Marek Marczykowski-Górecki wrote: > ... > > Sounds like https://github.com/QubesOS/qubes-issues/issues/5705 > > The fix is already in current-testing repository, and will be uploaded > > to

<    3   4   5   6   7   8   9   10   >