On Monday, February 26, 2018 at 12:14:02 AM UTC+1, Paul Mosier wrote: > Hi N, > > I did not find a better solution. I run the radio peripheral from sys-usb > directly and moved any software for it to that VM. > > Yuraeitha, my USB controller does not support PCI reset, so your ideas do not > help me. If sys-usb goes down the only way to get any USB functionality is > to reboot the system. And as this is a somewhat RAM-limited laptop, > switching the USB controller to any other VM doesn't always work, as sys-usb > doesn't always come up at boot (due to memory access issues). > > Incidentally, the Yubikey I have works just fine with qvm-usb. I didn't have > to do anything unusual for that at all. > > - Paul
Alright, so PCI reset is not supported. However, you haven't answered the full question in regard to the PCI reset, did you look at the feature to disable the PCI reset requirements? It's in the link awokd posted up above. As well as the method to make PCI more permissive too. You loose a bit security from local USB attacks, however, the question then becomes what you value more, as well as your threat profile, and if you ever leave your laptop/desktop alone/exposed to people you can't trust. Essentially, you may very well have the opportunity to remove the PCI reset requirement and add permissive mode to your USB, without loosing too much security, given if your environment is favorable (low attack risks on your machine). If you do that, then you won't need to restart the full machine every time you switch the controller, and sys-usb should work at every boot as well. Have you tried or thought about this? If this is no good, then direct USB attachment becomes a big hassle indeed. Interesting that you got the Yubi key to work with qvm-usb btw, I might have a second look at it again. It could be that I us Qubes 4 though? *shrug* I'll have to see what happens. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/4a688804-4196-490b-9af4-f3619036f03f%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.