Re: [qubes-users] Scary Systemd Security Report

2020-02-12 Thread Claudia
February 12, 2020 6:09 AM, ronp...@riseup.net wrote: > On 2020-02-11 11:39, unman wrote: > >> On Tue, Feb 11, 2020 at 01:34:15AM -0800, ronp...@riseup.net wrote: >>> I've been reading a blog from the renowned Daniel Aleksandersen at >>> https://www.ctrl.blog/entry/systemd-service-hardening.html

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread Claudia
February 9, 2020 8:52 PM, "Marek Marczykowski-Górecki" wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Sun, Feb 09, 2020 at 09:28:13AM -0800, brendan.h...@gmail.com wrote: >> On Sunday, February 9, 2020 at 5:25:56 PM UTC, brend...@gmail.com wrote: >>> >>> >>> Has anyone

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread Claudia
> marmarek: > This is a very bad idea to "fix" it. Those missing/changed CPUID bits later > on will cause issues. > And given most of the microcode updates recently are about speculative > execution, missing those > features will make the host vulnerable to those issues again. There are >

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread Claudia
February 9, 2020 9:52 AM, zachm1...@gmail.com wrote: > On Sunday, February 9, 2020 at 3:29:26 AM UTC-6, zach...@gmail.com wrote: > >> On Saturday, February 8, 2020 at 8:09:05 PM UTC-6, Marek >> Marczykowski-Górecki wrote: >>> If that's about something else, then fixing it would require finding

Re: [qubes-users] screenshot: send to VM ??

2020-02-08 Thread Claudia
February 8, 2020 12:19 PM, "haaber" wrote: >>> Hi, when I press PrintScreen (under xfce), I get several options, among >>> which save-in-dom0. It would be nice to be able to send it directly to a >>> VM. Can this be done? Cheers, Bernhard >> >> I haven't tested it, but try something like this:

Re: [qubes-users] How to install software in an AppVM without loosing persistence?

2020-02-08 Thread Claudia
February 8, 2020 11:51 AM, "Monsieur DuPont' via qubes-users" wrote: > Dear Qubes users/fans; > > I was trying the other day to install some piece of software in a Debian-9 > based AppVM but after a > reboot it was reset to its usual state and that piece of software was no > longer found. >

Re: [qubes-users] screenshot: send to VM ??

2020-02-08 Thread Claudia
February 8, 2020 9:01 AM, "haaber" wrote: > Hi, when I press PrintScreen (under xfce), I get several options, among > which save-in-dom0. It would be nice to be able to send it directly to a > VM. Can this be done? Cheers, Bernhard I haven't tested it, but try something like this: #!/bin/bash

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-07 Thread Claudia
February 7, 2020 8:10 PM, zachm1...@gmail.com wrote: > On Friday, February 7, 2020 at 2:07:34 PM UTC-6, zach...@gmail.com wrote: > >> On Friday, February 7, 2020 at 7:03:14 AM UTC-6, Claudia wrote: >>> February 7, 2020 6:00 AM, zach...@gmail.com wrote:> I have a Thinkp

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-07 Thread Claudia
February 7, 2020 1:03 PM, "Claudia" wrote: > February 7, 2020 6:00 AM, zachm1...@gmail.com wrote: > >> I have a Thinkpad T495 with an AMD Ryzen Pro 3700U and Vega 10 graphics. >> Everything seems to be >> working besides suspend/resume which is crucial for m

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-07 Thread Claudia
February 7, 2020 6:00 AM, zachm1...@gmail.com wrote: > I have a Thinkpad T495 with an AMD Ryzen Pro 3700U and Vega 10 graphics. > Everything seems to be > working besides suspend/resume which is crucial for me since I'm on the go a > lot. I had to build my > own Qubes R4.0 ISO to get the

Re: [qubes-users] Machine reboots when I log in

2020-02-05 Thread Claudia
February 5, 2020 7:34 AM, "Günter Zöchbauer" wrote: > When I come back to my computer > > and log in on the dom0 lock screen, the machine often just reboots. > > Has anybody seen this? > Any suggestions how to debug? You can try journalctl -b -1 -e, but it's probably not syncing the journal

Re: [qubes-users] cannot find if my hardware will meet the min requirements for the latest qubes os' install - need some help!

2020-02-05 Thread Claudia
February 4, 2020 4:40 PM, "unman" wrote: > At first setup do NOT choose to create a sys-sub - I've done it and it > is an unfortunate mistake to make. Last time I did a USB install (R4.1), the option was greyed out and "Unavailable because the root filesystem is on a USB device" or something

Re: [qubes-users] cannot find if my hardware will meet the min requirements for the latest qubes os' install - need some help!

2020-02-02 Thread Claudia
February 2, 2020 11:19 PM, "rickey" wrote: > Good evening Everyone, > > I have red about the minimum, and recommended system requirements for Qubes > OS latest installation > but still cannot define if my Intell NUC8i7HVK will meet them. > > Could you, please give me a help how to find if the

Re: [qubes-users] Custom guid.conf settings appear to be ignored

2020-02-01 Thread Claudia
February 1, 2020 7:21 PM, "awokd' via qubes-users" wrote: > Claudia: > >> I tried to increase my startup timeout in guid.conf according to >> https://www.qubes-os.org/doc/config-files > > Are you looking for qvm-prefs [vmname] qrexec_timeout? I wonder

Re: [qubes-users] Firefox discontinues addon sideloading

2020-02-01 Thread Claudia
February 1, 2020 9:13 AM, "David Hobach" wrote: > One could also follow their suggested path by setting up one's own addon > server; it sounds a lot like overkill to me though. I'm not sure if that would achieve the desired result though. I think that's no different from using the official

[qubes-users] Custom guid.conf settings appear to be ignored

2020-01-31 Thread Claudia
I tried to increase my startup timeout in guid.conf according to https://www.qubes-os.org/doc/config-files/ , but no matter what I change it to, the desktop notification still says cannot start after "60" seconds and `time qvm-start ...` still reports about a minute. Interestingly, the

Re: [qubes-users] Firefox discontinues addon sideloading

2020-01-31 Thread Claudia
January 28, 2020 7:09 PM, "David Hobach" wrote: > Dear all, > > apparently Mozilla decided to discontinue that feature [1] without providing > a lot of alternatives > [2]. > > It was quite useful in the past to update addons inside Qubes OS template VMs > by downloading them > to another VM

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-25 Thread Claudia
January 25, 2020 6:46 PM, "M" wrote: > Thank you very much ! - I’ll try that... > > By grub menu you probably mean this one: > https://www.qubes-os.org/attachment/wiki/InstallationGuide/grub-boot-menu.png > > But I do not get so far as it seems to first show after the installation. > > The

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-25 Thread Claudia
January 25, 2020 4:09 PM, "M" wrote: > 1) I have tried to install R4.0.3 in legacy mode with the same result. And I > have also tried the > other installation possibilities that the DVD offer with the same result. > Can I somehow save the logs on a USB-drive as I’m running the installer from >

Re: [qubes-users] feature request

2020-01-25 Thread Claudia
January 25, 2020 1:53 PM, "Chris Laprise" wrote: > On 1/25/20 7:15 AM, haaber wrote: > >> Hello, I have several virtual screens; I guess many user have. Is it >> possible to reserve one of them exclusively for dom0 and templateVM >> terminals -sort of a separated "admin screen"- to avoid other

Re: [qubes-users] feature request

2020-01-25 Thread Claudia
January 25, 2020 1:40 PM, "Claudia" wrote: > January 25, 2020 11:58 AM, brendan.h...@gmail.com wrote: > >> I think some window managers allow one to pin certain applications to >> particular virtual desktops. >> But those aren’t really security feature

Re: [qubes-users] feature request

2020-01-25 Thread Claudia
January 25, 2020 11:58 AM, brendan.h...@gmail.com wrote: > I think some window managers allow one to pin certain applications to > particular virtual desktops. > But those aren’t really security features, more just window manager tricks to > help users organize > windows. > > My preference

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-24 Thread Claudia
January 24, 2020 3:02 PM, "M" wrote: > I use DVD’s so that the files can’t be edited or a malicious file can’t be > placed on the > installation media in case it’s inserted in a compromised pc. But yes, it > seems to require a lot of > disc as Qubes OS not always develops linear. :j This is

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-24 Thread Claudia
January 24, 2020 12:55 PM, "M" wrote: > Thank you for your answer. > > What do you mean by “nomodeset” ? - is it regarding legacy and UEFI mode > or... ? In 4.0, to enable nomodeset you have to edit the bootloader files files in the installation media. I just realized, since you're using

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-23 Thread Claudia
January 23, 2020 4:57 PM, "M" wrote: > Hello Claudia > > It seems you got Qubes OS working with your AMD Ryzen 5 2500U with integrated > Vega 8 Graphics. > > I have bought a AMD Ryzen 3200G also with Vega 8 Graphics, and I have tried > install Qubes 4.0.1 and &

Re: Aw: Re: [qubes-users] Installation freezes before displaying installer - UEFI-Troublshooting impossible

2020-01-22 Thread Claudia
January 22, 2020 11:36 AM, anbe2...@joker.ms wrote: > Hello Claudia, > > thanks so much for your answer. > >> Once you write the image file with dd, you should be able to mount the ext3 >> /boot filesystem > read/write > >> just like you would any p

Re: [qubes-users] Upgrading/creating "special" VMs (sys-net, vault, etc)

2020-01-22 Thread Claudia
January 22, 2020 12:21 PM, "unman" wrote: > On Wed, Jan 22, 2020 at 03:09:31AM +, Claudia wrote: > >> January 21, 2020 7:04 PM, "Dan Krol" wrote: >> >> So to clarify: >> >> Sys-net and sys-firewall (and sys-vpn if you use it) wi

Re: Aw: Re: [qubes-users] Installation freezes before displaying installer - UEFI-Troublshooting impossible

2020-01-22 Thread Claudia
January 22, 2020 11:36 AM, anbe2...@joker.ms wrote: > Hello Claudia, > > thanks so much for your answer. > >> Once you write the image file with dd, you should be able to mount the ext3 >> /boot filesystem > read/write > >> just like you would any p

Re: [qubes-users] Installation freezes before displaying installer - UEFI-Troublshooting impossible

2020-01-21 Thread Claudia
January 22, 2020 2:48 AM, anbe2...@joker.ms wrote: > Hello Everybody, > > I want to install QubesOS R4.0.2 on a Tuxedo Book XC1510 (Intel i7-9750H, > Nvidia GeForce GTX > 1660Ti, 32 GB RAM, Samsung 970 EVO Plus M.2 SSD, insydeH2O BIOS 1.07.14RTR1) > > I downloaded the *.iso, multiple verified

Re: [qubes-users] Installation freezes before displaying installer - UEFI-Troublshooting impossible

2020-01-21 Thread Claudia
January 22, 2020 2:48 AM, anbe2...@joker.ms wrote: > Hello Everybody, > > I want to install QubesOS R4.0.2 on a Tuxedo Book XC1510 (Intel i7-9750H, > Nvidia GeForce GTX > 1660Ti, 32 GB RAM, Samsung 970 EVO Plus M.2 SSD, insydeH2O BIOS 1.07.14RTR1) > > I downloaded the *.iso, multiple verified

Re: [qubes-users] Upgrading/creating "special" VMs (sys-net, vault, etc)

2020-01-21 Thread Claudia
January 21, 2020 7:04 PM, "Dan Krol" wrote: > So to clarify: > >> Sys-net and sys-firewall (and sys-vpn if you use it) will need it enabled. > > When you say "need it enabled", you're just referring again to "provides > network", is that correct? > > And secondly: Do I understand correctly

Re: [qubes-users] Should I chose a TemplateVM or a StandaloneVM for a Windows 10 VM ?

2020-01-21 Thread Claudia
January 16, 2020 5:55 PM, "M" wrote: > I read about a TemplateVM and a StandaloneVM in the “Glossary of Qubes > Terminology”. But I’m still > not sure about which kind of VM to choose for a Windows 10 VM. > > Can someone please tell me more clearly when to chose these kinds of VM’s, > and

[qubes-users] Screen recording in Qubes VMs

2020-01-19 Thread Claudia
I was wondering if anyone has had any luck with recording screen captures in Qubes. I tried the following FFmpeg line, which worked fine except it's only capturing a 640x480 corner of the screen. I'm not sure if this is Qubes-related or if I'm just not using it correctly. Note, I'm running this

Re: [qubes-users] Why Windows 10 is slow? Is it because of HVM?

2020-01-19 Thread Claudia
January 19, 2020 6:34 AM, "Guerlan" wrote: > Windows 10 VM is considerably slower than my traditional PV VMs, the ones > that come with Qubes. In > fact no one would notice that my PV VMs are virtualized, they look just like > regular bare metal > machines. > However, Windows 10 has lags.

Re: [qubes-users] Re: Why Windows 10 is slow? Is it because of HVM?

2020-01-19 Thread Claudia
January 19, 2020 6:58 AM, "Claudio Chinicz" wrote: > Hi, > > As far as I understand, HVMs should be faster than PV. With the latter, the > OS makes hyper calls to > the hyper-visor while HVMs simply see virtualized hardware through the hyper > visor. I always thought the opposite was true.

Re: [qubes-users] How different from bare metal linux is Qubes NVME interaction?

2020-01-18 Thread Claudia
January 18, 2020 6:47 PM, "Guerlan" wrote: > On Saturday, January 18, 2020 at 8:27:05 AM UTC-3, Claudia wrote: > >> January 18, 2020 1:57 AM, "Guerlan" wrote:> I have a >> problem where any linux >> distro in my Razer Blade Stealth will suffe

Re: [qubes-users] Are there any security benefits of setting up standalonevm instead of appvm?

2020-01-18 Thread Claudia
January 8, 2020 6:28 PM, dhorf-hfref.4a288...@hashmail.org wrote: > "dont run software in places where you dont want it to run" should > cover this. note the term "run", not "install". In practice, I think there are some exceptions to this. Some software doesn't have a clear line between

Re: [qubes-users] How different from bare metal linux is Qubes NVME interaction?

2020-01-18 Thread Claudia
January 18, 2020 1:57 AM, "Guerlan" wrote: > I have a problem where any linux distro in my Razer Blade Stealth will suffer > from NVME corruption > (nvme enters in read only mode) many times a day. I tried the most recent > kernel, old ones, etc. > Tried opening a bug in canonical launchpad,

Re: [qubes-users] Xen doesn't recognize that a VM has finished starting

2020-01-15 Thread Claudia
January 14, 2020 12:29 PM, "tetrahedra via qubes-users" wrote: > I have a HVM VM that I'm trying to set up as a new sys-net. > > However, when I boot it, Xen / Qubes doesn't seem to recognize that the > domain has finished > starting. > > The Qubes menu at the top right shows the red

Re: [qubes-users] Autostart on login in minimal templates

2020-01-12 Thread Claudia
January 12, 2020 11:33 AM, "Abel Luck" wrote: > The systemd route does seem promising. Thanks. > > If I edited the template vm, I could just put my unit file in > /etc/systemd/system and it would work fine. > > However I'd like to do this for a specific AppVm, so I dropped the unit > file in

Re: [qubes-users] Re: Qubes 4 boot stuck at: "[ OK ] Reached target Basic System. "

2020-01-11 Thread Claudia
January 11, 2020 8:26 PM, cyber.citi...@tutanota.com wrote: > Thank you for your reply. If the problem recurrs, I would like to try this > solution before wiping > and reinstalling my entire system; but could you please provide a bit more > detail? How would I boot > with nomodeset? Boot into

Re: [qubes-users] Autostart on login in minimal templates

2020-01-11 Thread Claudia
January 11, 2020 2:06 PM, "Abel Luck" wrote: > Hi there, > > Using the fedora and debian minimal templates, how can I execute a > script on *login*? I'm aware of /rw/config/rc.local, but that runs on > system boot. > > Rather, I want to run something after X11 has initialized and my user is >

Re: [qubes-users] Debugging a sleep/suspend problem on Razer Blade Stealth 2016 - Qubes

2020-01-11 Thread Claudia
January 9, 2020 1:55 AM, "Guerlan" wrote: > First of all, here's the HCL for my Razer Blade Stealth 2016 4K touchscreen > 16gb RAM 512gb SSD: > https://groups.google.com/forum/#!searchin/qubes-users/razer$20blade|sort:date/qubes-users/PalZ-1inx > A/D3mQ4OI3CAAJ > > When I close the lid and

Re: [qubes-users] Re: Qubes 4 boot stuck at: "[ OK ] Reached target Basic System. "

2020-01-11 Thread Claudia
January 11, 2020 5:15 PM, cyber.citi...@tutanota.com wrote: > Yet another of my Qubes machines fell victim to this problem today. That's > two separate computers > in one week. The first was my production laptop. Today, it was my production > desktop. Of course, I > am inconvenienced by the

Re: [qubes-users] How to use QEMU with Qubes?

2020-01-08 Thread Claudia
January 7, 2020 7:43 PM, "Guerlan" wrote: > I undrstand that HVM uses QEMU to emulate some devices and BIOS. However, > what if I want to have > total control of QEMU? > > What if there's an OS for which there's a QEMU tutorial and I want to do > exact what is in the > tutorial but in Qubes?

Re: [qubes-users] Re: No Suspend/Resume on Dell Latitude 7400 (i5-8365U) with 4.0.2rc3

2020-01-08 Thread Claudia
January 8, 2020 12:10 AM, "Guerlan" wrote: > On Tuesday, January 7, 2020 at 8:41:31 PM UTC-3, Claudia wrote: > >> January 7, 2020 6:08 PM, "Guerlan" wrote:> On Monday, >> January 6, 2020 at >> 12:43:40 AM UTC-3, Claudia wrote: >>>

Re: [qubes-users] Re: No Suspend/Resume on Dell Latitude 7400 (i5-8365U) with 4.0.2rc3

2020-01-07 Thread Claudia
January 7, 2020 6:08 PM, "Guerlan" wrote: > On Monday, January 6, 2020 at 12:43:40 AM UTC-3, Claudia wrote: > >> January 6, 2020 3:14 AM, dmoe...@gmail.com wrote:> On Sunday, January 5, >> 2020 at 9:49:42 PM UTC-5, >> Guerlan wrote: >>>> ca

Re: [qubes-users] Default fedora-30 template asking for password that I don't have

2020-01-07 Thread Claudia
January 7, 2020 5:07 AM, fiftyfourthparal...@gmail.com wrote: >> Also, try using `su` with no arguments and see if that asks for a password >> also. > > The problem was resolved by using the "su" command on its own (as opposed to > "su user", which > prompted me for a password), which brought

Re: [qubes-users] Does the latest Linux kernel improve security for qubes?

2020-01-07 Thread Claudia
January 7, 2020 4:18 AM, "Chris Laprise" wrote: > On 1/6/20 4:11 PM, Claudia wrote: > >> January 6, 2020 8:20 PM, "Chris Laprise" wrote: >> On 1/5/20 11:30 PM, Claudia wrote: >>> >> >> I don't know much about PSP, or ME for that

Re: [qubes-users] Default fedora-30 template asking for password that I don't have

2020-01-06 Thread Claudia
January 6, 2020 8:45 PM, "Chris Laprise" wrote: > On 1/6/20 3:22 PM, Claudia wrote: > > I think s/he is really using a "minimal" template here. That would cause > sudo to be disabled by default. On these minimal templates, you can only > gain root privs

Re: [qubes-users] Does the latest Linux kernel improve security for qubes?

2020-01-06 Thread Claudia
January 6, 2020 8:20 PM, "Chris Laprise" wrote: > On 1/5/20 11:30 PM, Claudia wrote: > >> I don't know much about PSP, or ME for that matter, but it seems to me >> you're mostly screwed either >> way, so I figured I might as well save some money while I

Re: [qubes-users] Default fedora-30 template asking for password that I don't have

2020-01-06 Thread Claudia
January 6, 2020 5:02 AM, fiftyfourthparal...@gmail.com wrote: > Hello, Oops, I forgot to reply to this. Sorry. > I have a fresh installation of Qubes 4.0.2 on a Dell Inspiron 5593 with an > untouched fedora-30 > template. Aside from some minor hiccups during installation, no compatibility >

Re: [qubes-users] Qubes/Xen doesn't comply with IOMMU grouping rules for PCI passthru

2020-01-06 Thread Claudia
December 30, 2019 7:12 PM, "qubes123" wrote: >> The improper grouping is probably somewhere in AGESA, which is provided > >>> to the manufacturers by AMD. It could be because of hardware related >>> limitations, which again are supplied by AMD. Sometimes vendors take >>> liberties (cost cutting

Re: [qubes-users] Re: Perplexed, why do so many here seem to prefer Fedora instead of ?

2020-01-06 Thread Claudia
January 6, 2020 2:20 PM, "gorked" wrote: > To Morph this post a bit, being a lot of intrusions are now coming in with > the Web Browser, which > Web Browser is now the recommended one for Security? I have been using > Firefox, with a lot of > Addons, but I had to turn off the Java Script to

Re: [qubes-users] Does the latest Linux kernel improve security for qubes?

2020-01-06 Thread Claudia
January 6, 2020 5:16 AM, fiftyfourthparal...@gmail.com wrote: >> What can I say, I like doing things the hard way. > > Some might say it's good for character building--like climbing Everest with > minimal assistance when > you can instead just hire a bunch of Sherpas to carry you. > >> I don't

Re: [qubes-users] Does the latest Linux kernel improve security for qubes?

2020-01-05 Thread Claudia
January 6, 2020 3:52 AM, fiftyfourthparal...@gmail.com wrote: >> Inspiron 5575, AMD 2500U > > A newly-released machine with an AMD CPU and GPU? Are you a masochist or > someone who's looking to > perform feats of strength? (Like climbing Everest). Or is Intel really that > unpalatable for you?

Re: [qubes-users] Re: No Suspend/Resume on Dell Latitude 7400 (i5-8365U) with 4.0.2rc3

2020-01-05 Thread Claudia
January 6, 2020 3:14 AM, dmoer...@gmail.com wrote: > On Sunday, January 5, 2020 at 9:49:42 PM UTC-5, Guerlan wrote: >> can you tell me how you figured this out? I've been trying to fix a suspend >> bug in mine and It'd be >> helpful to know how you debugged things > > Mostly trial and error,

Re: [qubes-users] Feature request

2020-01-05 Thread Claudia
January 5, 2020 7:50 PM, "Franz" <169...@gmail.com> wrote: > May be it already somehow exists and I am not aware of it, but it would be > very interesting to be > able to save backup settings, that is a list of VMs that contain your current > ordinary activity and > you want to backup more

Re: [qubes-users] Does the latest Linux kernel improve security for qubes?

2020-01-05 Thread Claudia
January 5, 2020 12:30 PM, fiftyfourthparal...@gmail.com wrote: >> My HCL report for this machine is now almost six months in the making, all >> told. > > If an HCL report is taking someone with your level of knowledge six months to > compile, then it's > probably incredibly discouraging for

Re: [qubes-users] Does the latest Linux kernel improve security for qubes?

2020-01-04 Thread Claudia
January 5, 2020 3:14 AM, fiftyfourthparal...@gmail.com wrote: >> However there's probably no way to fully automate it. > > As someone somewhat knowledgeable about tech, but without deep knowledge, > this is annoying but > manageable. Should someone write a "First Boot Checklist" for the wiki,

Re: [qubes-users] Does the latest Linux kernel improve security for qubes?

2020-01-04 Thread Claudia
January 4, 2020 5:19 PM, dhorf-hfref.4a288...@hashmail.org wrote: > On Sat, Jan 04, 2020 at 09:01:35AM -0800, fiftyfourthparal...@gmail.com > wrote: >> Also, is there a quick diagnostic tool to check if a new installation on a >> new laptop have all functions working? (like sound, SLAT, TPM,

Re: [qubes-users] Problem during installation of Qubes 4.0.2

2020-01-04 Thread Claudia
January 4, 2020 12:28 PM, "Fabian" wrote: > Hello, > > I recently bought new hardware and tried to install Qubes on it, sadly > without any success at all. > > I tried it with UEFI only and with CSM (Compatibility Support Module) only, > but neither had worked. > > The media I used is the

Re: [qubes-users] "kfd kfd: error getting iommu info. is the iommu enabled?"

2020-01-04 Thread Claudia
January 4, 2020 9:35 AM, "awokd' via qubes-users" wrote: > Claudia: > >> I'm getting this message in my logs, about an IOMMU error, on both 4.0.2 and >> the F31-based 4.1 >> build. I'm as certain as I can be that the IOMMU is enabled in BIOS. I'm >>

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-03 Thread Claudia
January 3, 2020 5:53 PM, "Claudia" wrote: > January 1, 2020 5:09 PM, "Claudia" wrote: > >> However, I still have a long road ahead of me. I did several suspend/resume >> cycles, and each time I >> had a different combination of problems, in

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-03 Thread Claudia
January 3, 2020 7:17 PM, brendan.h...@gmail.com wrote: > On Friday, January 3, 2020 at 12:53:31 PM UTC-5, Claudia wrote: >> January 1, 2020 5:09 PM, "Claudia" wrote:I'll see if I >> can figure out how to >> apply the patch to the latest 4.1 (F31-based) and try

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-03 Thread Claudia
January 1, 2020 5:09 PM, "Claudia" wrote: > However, I still have a long road ahead of me. I did several suspend/resume > cycles, and each time I > had a different combination of problems, including the mouse sticking, the > keyboard not working, > and fi

Re: [qubes-users] Recommended laptop?

2020-01-01 Thread Claudia
December 31, 2019 1:02 PM, "eira wahlin" wrote: > I use qubes on an AMD system (thinkpad with Ryzen 5 pro 2500u). While I'm > happy with it, I've had > to make some sacrifices. AMD systems are tricky with hardware forwarding, so > I cannot (at the > moment) use a sys-USB. There is an inherent

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-01 Thread Claudia
December 30, 2019 6:44 PM, "qubes123" wrote: > Answering to your earlier question, my CPU capability information bits change > like this after > suspend: > > (XEN) Entering ACPI S3 state. > (XEN) AMD-Vi: Applying erratum 746 workaround for IOMMU at :00:00.2 > (XEN) Finishing wakeup from

[qubes-users] "kfd kfd: error getting iommu info. is the iommu enabled?"

2019-12-30 Thread Claudia
I'm getting this message in my logs, about an IOMMU error, on both 4.0.2 and the F31-based 4.1 build. I'm as certain as I can be that the IOMMU is enabled in BIOS. I'm having issues with passthru and I'm wondering if this might be the cause. In dom0 kernel logs: AMD IOMMUv2 driver by Joerg

Re: [qubes-users] Qubes/Xen doesn't comply with IOMMU grouping rules for PCI passthru

2019-12-29 Thread Claudia
December 29, 2019 2:19 PM, "awokd' via qubes-users" wrote: > Claudia: > >> December 26, 2019 12:59 PM, "awokd' via qubes-users" >> wrote: >> >>> Claudia: >>> >>> TLDR; check bottom of https://community.amd.com/thre

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-28 Thread Claudia
December 23, 2019 7:31 AM, "qubes123" wrote: > For many AMD systems (eg. Trinity/Richland) CPUID changes after suspend (some > of the high bits), > resulting in Xen Panic (see xen/arch/x86/acpi/power.c). So, more > investigation would be needed to > check why the CPUID bits are changing after

Re: [qubes-users] Can containers be saved and copied to another qubes install?

2019-12-28 Thread Claudia
December 28, 2019 7:13 PM, tobozoc...@gmail.com wrote: > Hi, > > Is it possible to take a container from Qubes that has some app installed and > copy it to another > system? > > Reason why this would be interesting, bc if containers can run windows apps > (thinking about > hardware

Re: [qubes-users] Lost USB-Controller, lost tty-credentials, emergency

2019-12-28 Thread Claudia
December 28, 2019 6:02 PM, mas...@tuta.io wrote: > my USB controller is attached to nothing, but needed for Yubikey login. > >> I lost my tty2-credentials (the username), so I'm locked out of the system. >> BIOS changes don't help. >> Is there any way to "free" USB during boot? Or get rid of the

Re: [qubes-users] Lost USB-Controller, lost tty-credentials, emergency

2019-12-28 Thread Claudia
December 28, 2019 5:20 PM, mas...@tuta.io wrote: > Dec 28, 2019, 17:42 by claud...@disroot.org: > >> December 28, 2019 4:31 PM, dhorf-hfref.4a288...@hashmail.org wrote: >> >>> On Sat, Dec 28, 2019 at 08:00:46AM -0800, mastor wrote: >> >> my USB controller is attached to nothing, but needed for

Re: [qubes-users] Lost USB-Controller, lost tty-credentials, emergency

2019-12-28 Thread Claudia
December 28, 2019 4:31 PM, dhorf-hfref.4a288...@hashmail.org wrote: > On Sat, Dec 28, 2019 at 08:00:46AM -0800, mastor wrote: > >> my USB controller is attached to nothing, but needed for Yubikey login. >> I lost my tty2-credentials (the username), so I'm locked out of the system. >> BIOS

Re: [qubes-users] Qubes/Xen doesn't comply with IOMMU grouping rules for PCI passthru

2019-12-27 Thread Claudia
December 26, 2019 12:59 PM, "awokd' via qubes-users" wrote: > Claudia: > > TLDR; check bottom of https://community.amd.com/thread/241650, looks > like there was a recently released related updated. Not sure if > applicable to your situation. Thanks for the link! I'm

Re: [qubes-users] HOWTO: Enable screen poweroff (instead of blanking)

2019-12-27 Thread Claudia
December 27, 2019 11:32 AM, dhorf-hfref.4a288...@hashmail.org wrote: > On Sun, Dec 22, 2019 at 02:45:34PM +0000, Claudia wrote: > >> overrides the XFCE Power Manager settings. Xscreensaver is only >> configured to blank the screen; I'm not sure if it even supports >> po

Re: [qubes-users] Re: Qubes/Xen doesn't comply with IOMMU grouping rules for PCI passthru

2019-12-27 Thread Claudia
December 27, 2019 11:37 AM, "John Mitchell" wrote: > "This can especially be the case with consumer class machines such as Ryzen." > I had to lol about this since I have had many Intel systems with one problem > or another and this is > certainly not isolated to Ryzen. I am also running a Ryzen

Re: [qubes-users] how to install or use pm-suspend similar command on Qubes

2019-12-27 Thread Claudia
December 27, 2019 8:35 AM, "awokd' via qubes-users" wrote: > Guerlan: > >> I'm following https://wiki.ubuntu.com/DebuggingKernelSuspend to debug >> kernel suspend problems. However, on dom0 there's no pm-suspend command. >> >> How can I install SECURELY this command or how to substitute for

Re: [qubes-users] upgrade: latest stable -> latest testing RC

2019-12-25 Thread Claudia
December 25, 2019 6:49 PM, taschent...@posteo.de wrote: > Hey. > > i have two questions: > > how can i upgrade from the latest stable release 4.0.1 to the latest RC 4.0.2- > rc3? The older upgrade guides, for instance > https://www.qubes-os.org/doc/upgrade-to-r4.0 look like i'd have to

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-24 Thread Claudia
December 23, 2019 7:31 AM, "qubes123" wrote: > Suspend/resume problem is most likely caused by a recently added security > feature in Xen, that > checks CPUID after resume with the previously (at boot time) known CPUID. > This is to ensure, that > the CPU microcode level - along with the

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-24 Thread Claudia
December 23, 2019 3:08 PM, "Brendan Hoar" wrote: > On Mon, Dec 23, 2019 at 9:46 AM Claudia wrote: > >> Awesome, in time for Christmas even! Downloading it now. Looks like it >> failed a few tests, so I >> don't know if it'll be usable enough to really test

Re: [qubes-users] Recommended laptop?

2019-12-24 Thread Claudia
December 24, 2019 12:51 PM, taschent...@posteo.de wrote: > On Tue, 2019-12-24 at 12:48 +0000, Claudia wrote: > >> Personally I would try to avoid AMD systems, > > why that? > > -- > You received this message because you are subscribed to the Google Gr

Re: [qubes-users] Recommended laptop?

2019-12-24 Thread Claudia
December 24, 2019 9:43 AM, "Ondřej Šulák" wrote: > Hello pals, > > for the last release of Qubes, what laptop would you recommend? Is there any > cheaper option which > does have HW compatibility with latest Qubes (ideally with shipping from EU), > than this one: > >

Re: [qubes-users] UPnP in Qubes

2019-12-23 Thread Claudia
December 23, 2019 6:09 PM, "hut7no' via qubes-users" wrote: > I have a setup like this: > AppVM -> FirewallVM -> NetVM -> internet > and want to be able to use UPnP for the AppVM. > Do any of you know how you would set this up in Qubes? > > -- You received this message because you are

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-23 Thread Claudia
December 23, 2019 1:17 PM, "qubes123" wrote: > As I remember, distribution releases (Fedora, Debian) without Xen were OK for > me, however, with > upstream Xen installed, obviously all had this suspend issue. > I don't have a debug card, so the symptoms are: when the computer wakes up > with

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-23 Thread Claudia
December 23, 2019 2:27 PM, "Brendan Hoar" wrote: > On Mon, Dec 23, 2019 at 6:45 AM Claudia wrote: > >> I'm not sure this is the problem, though, because I get the same symptoms >> when suspending in a >> Fedora 25 livecd. Which makes me think it's a Fe

Re: [qubes-users] wipe released diskspace of a disposable VM's

2019-12-23 Thread Claudia
brendan.h...@gmail.com: Other discussions involved performing the encryption inside the VMs, but as I mentioned earlier, if the content in the VM that is being manipulated is untrustworthy...then is the VM's internal encryption really trustworthy? This is a good point which I hadn't thought

Re: [qubes-users] Intel's continued security meltdown, MDS edition:

2019-12-23 Thread Claudia
Chris Laprise: From Kim Zetter at the New York Times: https://twitter.com/KimZetter/status/1194374230109868032 When Intel released patch for CPU vulns last May, it said the patch fixed all the vulns. But researchers at @vu5ec say this isn't true and Intel knew it. Intel asked them not to

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-23 Thread Claudia
December 23, 2019 7:31 AM, "qubes123" wrote: > Suspend/resume problem is most likely caused by a recently added security > feature in Xen, that > checks CPUID after resume with the previously (at boot time) known CPUID. > This is to ensure, that > the CPU microcode level - along with the

[qubes-users] Qubes/Xen doesn't comply with IOMMU grouping rules for PCI passthru

2019-12-22 Thread Claudia
I'm very new to all this iommu stuff, but as I understand it, devices in the same iommu group are supposed to be treated as a single unit, meaning if any of them are assigned to a VM then they all must be assigned to the same VM. This is because those devices cannot be isolated from each other

Re: [qubes-users] HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-22 Thread Claudia
December 22, 2019 5:45 PM, "Vít Šesták" wrote: > Helllo, > > Dec 22, 2019 15:17:27 Claudia : > > >> I don't know which step -- unbinding xhci_pci, or binding pciback -- >> actually causes the crash in > this case. I can say, however, that one of them

[qubes-users] HOWTO: Enable screen poweroff (instead of blanking)

2019-12-22 Thread Claudia
I just wanted to drop a note here before I forget. Out of the box, Qubes blanks the screen after a few minutes, but never powers off the screen, even though it's configured to do so in the XFCE Power Manager. I've had this problem on several machines, all the way back to R3.2, and I always

Re: [qubes-users] HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-22 Thread Claudia
December 22, 2019 10:33 AM, "Vít Šesták" wrote: > As far as I know/understand: > > * At start, all the PCI devices are assigned to dom0. > * When a qube with an attached PCI device starts, dom0 assigns the PCI device > to the qube, so it is > no longer attached to dom0. It never gets actually

Re: [qubes-users] Dual booting Qubes and Qubes?

2019-12-21 Thread Claudia
December 20, 2019 2:19 PM, "Claudia" wrote: > > I decided I'm going to try the dual-ESP approach first and see if it works. > If not, then I'll try > the EFI directory hack. > > I formatted my disk like: ESP, /boot, root, ESP, /boot, root, (swap); and > install

Re: [qubes-users] HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-21 Thread Claudia
December 20, 2019 9:13 PM, "Claudia" mailto:claud...@disroot.org?to=%22Claudia%22%20)> wrote: December 20, 2019 6:05 PM, brendan.h...@gmail.com (mailto:brendan.h...@gmail.com) wrote: On Friday, December 20, 2019 at 9:29:55 AM UTC-5, Claudia wrote:December 19, 2019 12:13 AM, &qu

Re: [qubes-users] HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-20 Thread Claudia
December 20, 2019 6:05 PM, brendan.h...@gmail.com (mailto:brendan.h...@gmail.com) wrote: On Friday, December 20, 2019 at 9:29:55 AM UTC-5, Claudia wrote: December 19, 2019 12:13 AM, "Claudia" wrote: > This is R4.1 build 20191013 > > It works pretty well, definit

Re: [qubes-users] HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-20 Thread Claudia
December 19, 2019 12:13 AM, "Claudia" wrote: > This is R4.1 build 20191013 > > It works pretty well, definitely better than 4.0, but there are some weird > boot issues. If I let it > boot with everything as default, it will boot loop before reaching the disk > pass

Re: [qubes-users] Dual booting Qubes and Qubes?

2019-12-20 Thread Claudia
December 19, 2019 3:44 PM, "awokd' via qubes-users" wrote: > Claudia: > >> My original thought was to just give each one its own directory in >> /boot/efi/EFI/, but the /boot/efi/EFI/qubes/ path seems to be hard coded >> somewhere, probably either in the

[qubes-users] HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-18 Thread Claudia
This is R4.1 build 20191013 It works pretty well, definitely better than 4.0, but there are some weird boot issues. If I let it boot with everything as default, it will boot loop before reaching the disk password screen. I found I can get it to boot successfully if I add to the Xen commandline

  1   2   >