Re: [qubes-users] Qubes 4: Syntax Error in qubes.GetAppmenus during every package install

2018-10-27 Thread Otto Kratik
On Saturday, October 27, 2018 at 10:43:15 PM UTC-4, unman wrote:
> On Sat, Oct 27, 2018 at 07:39:10PM -0700, Otto Kratik wrote:
> > Qubes 4.0
> > 
> > Any time I use apt-get to install software into a debian-type TemplateVM 
> > (Debian-9, Whonix GW or WS), I always get the following error during the 
> > installation phase:
> > 
> > Processing triggers for qubes-core-agent (4.0.37-1+deb9u1) ...
> > 
> > /etc/qubes-rpc/qubes.GetAppmenus: 20: /etc/qubes-rpc/qubes.GetAppmenus: 
> > Syntax error: "(" unexpected
> > 
> > 
> > As a result, the software is installed correctly but the App menu shortcuts 
> > are not sent to the dom0 menus or Applications List of the relevant 
> > Template or related AppVMs, and I have to do qvm-sync-appmenus manually 
> > from the dom0 terminal every time. That command works fine with no errors, 
> > and the new shortcut entries appear as expected.
> > 
> > Installing new software packages in Fedora templates work fine and do not 
> > cause any issues, it is only Debian type templates that are affected.
> > 
> > What is causing this issue and how is it corrected?
> > 
> 
> It's a known issue, (#4417) and the fix is already in the pipeline.
> You can work around by calling qvm-sync-appmenus  from the
> command line.
> 
> unman

Thanks, I'm glad at least to hear that it's universal and not a specific fault 
related to my particular installation. I will just wait for the fix and use the 
workaround in the meantime.

Appreciate the quick and helpful reply.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/b05a6c0f-3ede-4b91-a34c-c25b9939a818%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Re: Ubuntu templates

2018-10-27 Thread unman
On Fri, Oct 26, 2018 at 03:23:34PM -0700, Patrick wrote:
> On Monday, October 8, 2018 at 9:28:26 AM UTC-5, unman wrote:
> > It's now straight forward to build templates for bionic as well as xenial,
> > using qubes-builder.
> > 
> > If you want to try them out before building, I've uploaded freshly built
> > templates for 4.0, including a fairly hefty xenial-desktop template.
> > You can find details at https://qubes.3isec.org 
> > 
> > Updated packages are available from the repositories there, if you
> > already have a working template.
> > 
> > unman
> 
> Hi, I came to find this answer too, what is the best way to install an ubuntu 
> vm?
> 
> Also, just fyi, I want to run the VMware-Horizon-Client in order to run VDI. 
> Documentation says it's tested on ubuntu and Red Hat.
> 
> Thanks,
> Patrick
> 
You can build your own template using qubes-builder.
Instructions for that are in the docs:
https://www.qubes-os.org/doc/qubes-builder

Use ./setup to select the ubuntu version you want, then make qubes-vm and
make template will produce a new template.
Actually, the build is broken at the moment while I figure out how best
to deal with incorporating apt-transport-https in to the build, and mix
in security updates.

In the meantime you can download some prebuilt Ubuntu templates from
https://qubes.3isec.org/

Whatever route you take, transfer the template to dom0 and install it
using dnf install 

unman


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20181028025154.umdsl5wgkedhu6lo%40thirdeyesecurity.org.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Qubes 4: Syntax Error in qubes.GetAppmenus during every package install

2018-10-27 Thread unman
On Sat, Oct 27, 2018 at 07:39:10PM -0700, Otto Kratik wrote:
> Qubes 4.0
> 
> Any time I use apt-get to install software into a debian-type TemplateVM 
> (Debian-9, Whonix GW or WS), I always get the following error during the 
> installation phase:
> 
> Processing triggers for qubes-core-agent (4.0.37-1+deb9u1) ...
> 
> /etc/qubes-rpc/qubes.GetAppmenus: 20: /etc/qubes-rpc/qubes.GetAppmenus: 
> Syntax error: "(" unexpected
> 
> 
> As a result, the software is installed correctly but the App menu shortcuts 
> are not sent to the dom0 menus or Applications List of the relevant Template 
> or related AppVMs, and I have to do qvm-sync-appmenus manually from the dom0 
> terminal every time. That command works fine with no errors, and the new 
> shortcut entries appear as expected.
> 
> Installing new software packages in Fedora templates work fine and do not 
> cause any issues, it is only Debian type templates that are affected.
> 
> What is causing this issue and how is it corrected?
> 

It's a known issue, (#4417) and the fix is already in the pipeline.
You can work around by calling qvm-sync-appmenus  from the
command line.

unman

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20181028024312.2qppjfyidk6lu2fp%40thirdeyesecurity.org.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Qubes 4: Syntax Error in qubes.GetAppmenus during every package install

2018-10-27 Thread Otto Kratik
Qubes 4.0

Any time I use apt-get to install software into a debian-type TemplateVM 
(Debian-9, Whonix GW or WS), I always get the following error during the 
installation phase:

Processing triggers for qubes-core-agent (4.0.37-1+deb9u1) ...

/etc/qubes-rpc/qubes.GetAppmenus: 20: /etc/qubes-rpc/qubes.GetAppmenus: Syntax 
error: "(" unexpected


As a result, the software is installed correctly but the App menu shortcuts are 
not sent to the dom0 menus or Applications List of the relevant Template or 
related AppVMs, and I have to do qvm-sync-appmenus manually from the dom0 
terminal every time. That command works fine with no errors, and the new 
shortcut entries appear as expected.

Installing new software packages in Fedora templates work fine and do not cause 
any issues, it is only Debian type templates that are affected.

What is causing this issue and how is it corrected?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/ac43deca-a3fd-4beb-8c3c-f915867464f6%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: Thinkpad X1 Carbon Gen6 suspend/resume issues

2018-10-27 Thread tfm853 via qubes-users
On Saturday, October 27, 2018 at 8:57:43 AM UTC-4, tfm...@googlemail.com wrote:
> To be more precise regarding the wifi and USB issues:
> 
> One following issues can occur after suspend:
> 
> - All USB devices disappear from sys-usb, wifi is not working anymore. This 
> can be fixed by restarting both sys-usb and sys-net.
> 
> - Directly after suspending, the speaker plays a loud, short melody (sounds a 
> bit like the game-over-sound of an 80s computer game ^^). I guess this is 
> some kind of diagnostic code? The LED shows sleep but the fan might keep 
> running when it was running while suspending. The system cannot be woken up 
> by opening the lid or pressing the power button.
> 
> The interesting part is: Either of these issues only seems to appear when a 
> win7 HVM is running.

More precisely: If I just start an empty HVM (it will run a couple of seconds 
before it shuts down again) and suspend while it is running, the issue appears 
too.

On the other hand, after I installed qubes-windows-tools in my win7hvm, I can 
run that HVM and suspend without issues.

A bit of pseudo-science: On the surface, the difference would be that an HVM is 
shown as 'transient' all the time whereas with QWT the HVM will show proper 
states.

Anyways, it fixes the issue for me. So I guess I'm happy now. :-)

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/b3c3ecf1-d285-4114-b8ee-8f415825016c%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Re: Thinkpad X1 Carbon Gen6 suspend/resume issues

2018-10-27 Thread Ranguvar
On Sat, Oct 27, 2018, 16:19  wrote:

> On Saturday, October 27, 2018 at 5:57:43 AM UTC-7, tfm...@googlemail.com
> wrote:
> > To be more precise regarding the wifi and USB issues:
> >
> > One following issues can occur after suspend:
> >
> > - All USB devices disappear from sys-usb, wifi is not working anymore.
> This can be fixed by restarting both sys-usb and sys-net.
> >
> > - Directly after suspending, the speaker plays a loud, short melody
> (sounds a bit like the game-over-sound of an 80s computer game ^^). I guess
> this is some kind of diagnostic code? The LED shows sleep but the fan might
> keep running when it was running while suspending. The system cannot be
> woken up by opening the lid or pressing the power button.
> >
> > The interesting part is: Either of these issues only seems to appear
> when a win7 HVM is running.
> >
> > With only linux appvms running, I can close/open the lid 10 times (not
> that big of a sample, but still) without issues.
> >
> > With a win7 HVM running, one of the issues happens everytime.
> >
> > I don't have any other HVMs. But I guess this isn't predicated on win7
> specifically.
>
> Did you try the suspend/resume fix that DJB documented here:
> https://groups.google.com/d/msg/qubes-users/TmGDlkluJgM/1BFsQZWNDAAJ
>
> It requires recompiling the kernel, but took me about 2 hours in total
> from reading, to understanding, to doing this in total on the same machine.
> It has worked for several of us (don't know anyone that it didn't work
> for). I have read that BIOS 1.31 should fix suspend/resume issues, but
> haven't tried it yet.
>
> I haven't run a win7hvm or tried thermal issue fixes either.
>

That patch forces S3 support on.
I've been using patches like that and patches to the DSDT so the laptop
signals S3 for months.

It's not needed with the new BIOS that allows controlling that.
Should not play any role in this whatsoever.

I have not used HVMs.

>

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAHe59t7URDnUGLMxHcdd2TwAz-WYk9TG5s%2B3-pOm6xP_ZN1w2Q%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: Thinkpad X1 Carbon Gen6 suspend/resume issues

2018-10-27 Thread fiasco4297
On Saturday, October 27, 2018 at 5:57:43 AM UTC-7, tfm...@googlemail.com wrote:
> To be more precise regarding the wifi and USB issues:
> 
> One following issues can occur after suspend:
> 
> - All USB devices disappear from sys-usb, wifi is not working anymore. This 
> can be fixed by restarting both sys-usb and sys-net.
> 
> - Directly after suspending, the speaker plays a loud, short melody (sounds a 
> bit like the game-over-sound of an 80s computer game ^^). I guess this is 
> some kind of diagnostic code? The LED shows sleep but the fan might keep 
> running when it was running while suspending. The system cannot be woken up 
> by opening the lid or pressing the power button.
> 
> The interesting part is: Either of these issues only seems to appear when a 
> win7 HVM is running.
> 
> With only linux appvms running, I can close/open the lid 10 times (not that 
> big of a sample, but still) without issues.
> 
> With a win7 HVM running, one of the issues happens everytime.
> 
> I don't have any other HVMs. But I guess this isn't predicated on win7 
> specifically.

Did you try the suspend/resume fix that DJB documented here: 
https://groups.google.com/d/msg/qubes-users/TmGDlkluJgM/1BFsQZWNDAAJ 

It requires recompiling the kernel, but took me about 2 hours in total from 
reading, to understanding, to doing this in total on the same machine. It has 
worked for several of us (don't know anyone that it didn't work for). I have 
read that BIOS 1.31 should fix suspend/resume issues, but haven't tried it yet.

I haven't run a win7hvm or tried thermal issue fixes either.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/db0a40ea-0813-4540-989e-2df8a69e9af0%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Additional USB controllers for a laptop expresscard to PCI-slots

2018-10-27 Thread taii...@gmx.com
On 10/24/2018 01:41 AM, 'awokd' via qubes-users wrote:
> 
> 
> Unman:
>> On Mon, Oct 22, 2018 at 10:40:23AM -0300, Franz wrote:
>>> On Mon, Oct 22, 2018 at 10:29 AM unman 
>>> wrote:
>>>
 On Mon, Oct 22, 2018 at 09:13:46AM -0300, Franz wrote:
> On Mon, Oct 22, 2018 at 12:42 AM taii...@gmx.com 
 wrote:
>
>> No it won't.
>>
>> Expresscard > PCI-e
>>
>> PCI anything WILL NOT WORK - ALL IN SAME IOMMU GROUP.
>>
>> Save money buy one marketed for egpu gaming for $100 or so from bplus
>> tech taiwan - expresscard>pci-e then buy a Sonnet Allegro Pro
>> which is
 4
>> separate USB controllers which will work fine AS LONG AS YOUR LAPTOPS
>> ROOT PORTS SUPPORT ACS otherwise it won't work they will all be the
 same
>> group. I have no idea what laptops do however.
>>
>>
> It seems my processor i7 3520m does not support ACS. So this should
> mean
> that even if I use 4 different PCI cards, in the best case scenario
> they
> can only be assigned to the same VM.
>
> On the same laptop Lenovo x230 a similar problem was that it has two
 native
> USB controllers, but there is some connection between them so that
> they
 can
> only be assigned to the same VM.
>

 Not in my experience with x230. Three controllers, and you can separate
 ports on Left and Right between two usbVM.

>>>
>>> with 3.2 or 4?
>>> I tried various times with 3.2 and it replies something like that it
>>> does
>>> not want to do that because the two controllers are somehow connected
>>> and
>>> therefore there is a security risk isolating them when they are not
>>> really
>>> isolated.
>>>
>>> But of course you understand all that much better than me Unman :-)
>>>
>>
>> Blind leading the blind, I'm afraid.
>>
>> This is with 4. I'll try it with 3.2.1 in the morning.
>>
> @taiidan- I based that from some code I saw in Xen that seemed to
> support classic PCI passthrough. See also the last entry on this page
> for example: https://wiki.xen.org/wiki/Xen_PCI_Passthrough. Agree it's
> not the most secure approach with Qubes, if it works at all.

All of the controllers all be in the same IOMMU group in that case due
to a PCI bridge so pointless for what he wants aka separate usb controllers.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/59fc7419-0d2b-d27a-056b-61768683fbd8%40gmx.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Replacement for Lenovo x230 (coreboot'able + high res)

2018-10-27 Thread taii...@gmx.com
On 10/26/2018 07:28 PM, 799 wrote:
> Hello,
> 
> I have used two x230 (i5 and i7) in the last email years to run Qubes.
> While I love the form factor and battery runtime I would like to move to a
> device which has a better screen resolution.
> I'd like to have something between 12 and 14inch as I have already a bigger
> 15,4" laptop which has a great resolution (3K) but bad battery runtime
> (Workstation Laptop).
> 
> Do you have a suggestion which fits into my wishlist:
> 
> - Coreboot'able
> - Qubes 4 compatible
> - FullHD Resolution 1.920x1.080 or similar
> - 16 GB RAM
> - optional LTE WAN Card
> - 12 or 14 inch
> - good battery runtime

Get a T430 (get a better kb from *20 series) or a W520 and install an
ivy-bridge CPU and a screen upgrade if you can't find one that comes
with the res you want - there are some nice aftermarket ones from china
and taiwan but the W series should have a 1920 oem model. Of course get
one without the dGPU to save battery power...you can get an eGPU via
ExpressCard if you want more video juice etc.

There is a wwan pci-e port card and a sim slot on both afaik and since
it is restricted via IOMMU there should not be any security issues.

You can install a second slice battery on the bottom.

Both work fine with coreboot-openhwinit and me cleaner to nerf the me
(disabling always impossible) and will work with qubes 4.0 features.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/67291288-b86b-7dba-1a05-44e89b3ce9d7%40gmx.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] My farewell to Qubes OS!

2018-10-27 Thread taii...@gmx.com
No!! comp-sci angel D: you are IMO the best computer security
person on the planet and now you leave us :'[

You can't trust the "cloud" - it will always be someone elses computer

SGX etc is DRM and a proprietary wintel technology that shouldn't be
trusted.

You should look in to intergricloud and FlexVER which are made by raptor
computing systems the makers of the OpenPOWER TALOS 2, Blackbird and
various libre firmwares.

Heres to hoping for qubes on POWER, which is the only owner controlled
high performance computing platform and freer than x86 ever was with
more documentation than x86 ever had.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/53c1799a-5d36-28ed-9945-9b466a2ba72d%40gmx.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] My farewell to Qubes OS!

2018-10-27 Thread Ángel
Thanks for all your work, Joanna!

Good luck at the Golem Project.
I am sure that having you on board it will feature many 'interesting'
properties that otherwise it wouldn't.

Remember to s/‎אמת/‎מת‎/ should you have trouble with the golems 😉

Best regards

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/1540660835.969.12.camel%4016bits.net.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: My farewell to Qubes OS!

2018-10-27 Thread drogo
On Thursday, October 25, 2018 at 6:21:51 AM UTC-4, Joanna Rutkowska wrote:
> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA256
> 
> Hello Qubes devs and users!
> 
> It's been nearly 9 years[*] since I sent the first internal email
> within ITL to Rafał Wojtczuk and Alex Tereshkin with the original idea
> for making Qubes OS. Shortly after this, we started drafting the
> original architecture and writing some early PoC code...
> 
> Today, I've made an announcement I'm switching focus to another area
> of work and joining the Golem Project as a Chief {Strategy, Security}
> Officer:
> 
> https://www.qubes-os.org/news/2018/10/25/the-next-chapter/
> 
> https://blog.golemproject.net/joanna-rutkowska-joins-golem-as-chief-strategy-security-officer-13f12f0c11c0
> 
> I'd like to thank all the people who made Qubes OS possible, which
> includes: the whole ITL team, all the community contributors, and, of
> course, all the Qubes OS users!
> 
> Qubes OS will continue under the lead of Marek Marczykowski-Górecki,
> who have been a de-facto lead for all the day-to-day development for
> quite some time already!
> 
> Thanks, Marek! Thank you, all!
> 
> Cheers,
> joanna.
> 
> [*] FWIW, the exact date was November 11th, 2009.
> -BEGIN PGP SIGNATURE-
> 
> iQIzBAEBCAAdFiEEtR14vbBDAuE0X2Ly1F2dklVl1NIFAlvRmTYACgkQ1F2dklVl
> 1NIiDxAAtwm3qM1Rq3ow67q5bLu+1VnuM0NQrN/crLu+FDOdaa9XNzSsdWz97UoN
> 2VsRO+RICNttrR7MAaWSgTXtBKOMuSXYc7s5r7VVFtx4qW0xyRaxbr7vBqJRDM5n
> 6eCLdjAFf1Xh8Ju5eDnBJGx41EIywO4Jba3z9+Ww2xyBycQAYY22yRQf6ANlWfwW
> XE0HgBuaJtAEReJc7qpzlG/iwLa/de1eqVa9kOS4HrESllE9wP7qXLrnmwr/yH19
> 2twe3QVS29uVYzPOam6PiCg1PN4AjsYKvihy/Tap11bYfdr1L8OjmE9+KrDPFPek
> MaWlkl/OoiFZsQHhj1somMfFNKH82oTW3zIAZCmmOZgQHgt6T1KDzjehFTASJeFp
> WNmvmowDYfcVYEdjEXQKP78mpxlYz6fChr/A4x3TX64+KsltdZA7l266OMfpXvL4
> Mja4SUvEKqLbyEQxCaDnOwm4cV7k/dHtOXE5fREzUfi+YVu14yVNkPRxg9UpgtCa
> sV/PY7AwOe4JqxV+8VlWWmX0amNf8ZEtz51F2eH6NZZYGaRtTXxTKW6Aad0XHg7p
> 8m2gvH8YWnGPX7ckofcpL7NHR5B6EauXoHKeQZgV9Ix0NQf2CNvBv5ZxZ7IYannH
> mJEcpgRYMtG5b8+x05hBCb7CP5T/tQpt2r5jIK3eqwEzcPY//H8=
> =1ZqA
> -END PGP SIGNATURE-

Congratulations on your new position!!

I've been using Qubes for a couple of years, and just wanted to say THANK YOU 
for all your work on it! It really fits well with my usage model and makes my 
life a great deal more convenient.

Wishing you all the best in your new role!

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/1d2b9450-a01d-4eda-a95d-94f0282458ab%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: Thinkpad X1 Carbon Gen6 suspend/resume issues

2018-10-27 Thread tfm853 via qubes-users
To be more precise regarding the wifi and USB issues:

One following issues can occur after suspend:

- All USB devices disappear from sys-usb, wifi is not working anymore. This can 
be fixed by restarting both sys-usb and sys-net.

- Directly after suspending, the speaker plays a loud, short melody (sounds a 
bit like the game-over-sound of an 80s computer game ^^). I guess this is some 
kind of diagnostic code? The LED shows sleep but the fan might keep running 
when it was running while suspending. The system cannot be woken up by opening 
the lid or pressing the power button.

The interesting part is: Either of these issues only seems to appear when a 
win7 HVM is running.

With only linux appvms running, I can close/open the lid 10 times (not that big 
of a sample, but still) without issues.

With a win7 HVM running, one of the issues happens everytime.

I don't have any other HVMs. But I guess this isn't predicated on win7 
specifically.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/6351ea7e-eb0a-48bb-976e-535cde426731%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Qubes User Forum

2018-10-27 Thread Zrubi
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA256

On 10/26/18 10:18 PM, Zrubi wrote:
> On 10/26/18 9:52 PM, Zrubi wrote:
>> It seems if you using the google "forum" interface, then the from
>>  header looks like this:
> 
>> From: "'Raffaele Florio' via qubes-users" 
>> 
> 
> Or probably not even the forum interface, but the standard webmail 
> with multiple email address/alias?
> 
> Can you confirm how you post your mails to this list please?

I just found the root cause:

https://www.spamresource.com/2014/04/google-groups-rewriting-from-addres
ses.html

As you are not the only one having this issue, I might be creating a
patch for fudforum to handle this madness.

- -- 
Zrubi
-BEGIN PGP SIGNATURE-

iQIzBAEBCAAdFiEEmAe1Y2qfQjTIsHwdVjGlenYHFQ0FAlvUUxcACgkQVjGlenYH
FQ3wNg//Vhibw6JJ8YoPACPyJF8WPItbOzR6vg9b8vLdPVut1jrEUwbuNuuRgZf9
CV8BIWuSGKaGJ/yua9V5TiETpQmTjafQVqm7qP6jIdw3F8g5LGvABCiISRUwKfPQ
IS16YybwG1RDm2/81ZL5rbaowqfn1wYOf2WgFV/rPgyi6jXsXXo9SAlgXeAd6SVx
gEdFQ6/8/UQ8sEGYJlGtSXgm71XPRcP2QR9eJSHx/BVFCcuOgY/sJCTJdeVT9GmS
BA/QuhKzYBfvcOjE/avuGhUhgFTuSGABhTHE3Of3ylfU2X0yOi3wI8XZzD1Zc93I
Z/iuy9IPTc1098pwBoWV4i5NZFBBJAH3LDvSYuuZHFAXpzuZuxQvbjvryKCUJpuJ
JJ5LgkfdEv9wk9YCjd+IJmmN6U92vc2uRw78O/JIn2ktafpVP+OCrPK7getMraC0
SBdV7915DjI5/N2+4VoIQrTJZmibhQyX8IhThET8H9iyZxh8L7r2jRLxwj9TOCx9
zgbY0/fZ6fdBcQ7BEEO4GSrSLu7m/aVGP5Q3YNNnRpG1Da4LJK/LEVEZAH0LaEKk
dRMX8FD8Dev2qNHE3MLtIMG0SZPVS5uvsJAfH2jiD7/e8NH+zbwgrTb2BYJn1oj0
nLpWvLbeVY5BborhEyN68wnosoVJxqHwQ+dicsWacT4sioxIdpU=
=zLHP
-END PGP SIGNATURE-

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/9fbee19e-6f1d-91cc-cd1f-fa1ae9763877%40zrubi.hu.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: Qubes 4 AMD Microcode

2018-10-27 Thread qubes-os

Thanks for the response.

I was more trying to find out if the microcode updates provided by Qubes 
include all of the processor families that AMD has released.


For some families, the version appears to be old (at least based on what 
is listed via cpuinfo) so was wondering if it was an update issue or if 
what is provided by Qubes doesn't include all the processor families 
released.



--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/7c9965ca-d09e-d809-8a60-3117d61799f6%40go-bailey.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Selinux

2018-10-27 Thread birdynam
Hi,

why selinux is not activated on fedora template used by Qubes and dom0 ?

Birdy.





-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/9e1e0d18-e4f6-39d1-b1be-a05a169d27ab%40gmail.com.
For more options, visit https://groups.google.com/d/optout.


signature.asc
Description: OpenPGP digital signature


[qubes-users] Re: Replacement for Lenovo x230 (coreboot'able + high res)

2018-10-27 Thread superriku11
All of the **30 series ThinkPads were supported by Coreboot, last I checked. 

The T430 has a 14-inch screen, but not FHD resolution like you would like. 
There is a screen replacement that some people have done to upgrade it to 1920 
x 1080.
http://www.thinkwiki.org/wiki/Replacing_T430_screen_with_a_better_one

If you'd rather not replace the screen, there's also a ThinkPad W530, which has 
a 15-inch screen, and you can get in OEM configuration with a 1920 x 1080 
resolution. 

Either option should support the features required by Qubes 4.0. I personally 
have not tested them with Coreboot though, and there are certain compatibility 
issues with some hardware. I can't guarantee you that it works, but the 
features are there and should work under the OEM firmware even if not under 
Coreboot.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/52e26396-1b76-4d0b-ac0c-a1e250df77ca%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] My farewell to Qubes OS!

2018-10-27 Thread donoban
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA256

On 10/25/18 12:21, Joanna Rutkowska wrote:
> Hello Qubes devs and users!
> 
> It's been nearly 9 years[*] since I sent the first internal email 
> within ITL to Rafał Wojtczuk and Alex Tereshkin with the original
> idea for making Qubes OS. Shortly after this, we started drafting
> the original architecture and writing some early PoC code...
> 
> Today, I've made an announcement I'm switching focus to another
> area of work and joining the Golem Project as a Chief {Strategy,
> Security}

Ouch I skipped this thread.

Sad to see you go. After writing Qubes Air post you go to protect the
cloud... Are you really leaving? :)

Thanks for all Joanna. Best of luck in Golem.
-BEGIN PGP SIGNATURE-

iQIzBAEBCAAdFiEEznLCgPSfWTT+LPrmFBMQ2OPtCKUFAlvUOYkACgkQFBMQ2OPt
CKUmPA/+KGEaIqCY1CEZq/mq0/QUKx+jpUl8GFYW7ST9e+XIMx1uLNAbYSR2QLd0
o3oovDT+2joVVk38GjzHw6sN5Z/bKOpDmm2KJ4811ReAFnIbtehW4y+nlehabCAM
aAykoD0vw/m7jhcJ7Lc2D/ijpsv7hTwNgk0/ueuu0pWkwLU5rJCgy0sIQHUcnMte
zQX2tL4xLeL/Ckvx9oRJJs5nUO3qZzYsItAAX1Z/dwa3J2f4ry1yYkdeL5k56l9v
QacnunRfrcTyK6SbDa4d0u6zezSd0HH12ISZISB1RyagldOOA+jFMUt6y3qJ/IXe
o8wiXLiU338cwIdDn5auNurcCQcx/BxKuvD7ziP2NIRdZtz3DWJcAonlQhmBBwOI
lDBg8wiWjHHKJWkgSCSv3gttkAl9vfygge7UAn8COiT/KTzupd4zSAm586Q6l3aD
e4l6es05jBjub0NBiKRLjFpMQFAl3+0QBlvpFNhlIGFlm63sVpdTPMwc3rr4u4KD
Rd7ld6jrghUVL07eXvHx6H3HJjjQNdgdLxqn6P2sRQZ2S7omM2mri0/L/szyThy1
Z58yBh7Wj5EVPZhhSrpQzOpd9bOrXs3mGeuNzuyo/+ZE2fO8V119LlNntnmET3nI
srIGcZx/a+3BfmvBM1Feb6UXgsC3de0myB9pWASR+jfkCY3ZahE=
=pbXo
-END PGP SIGNATURE-

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/49337e5e-e3f6-cf28-a4b2-4306dbf278a4%40riseup.net.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Replacement for Lenovo x230 (coreboot'able + high res)

2018-10-27 Thread 799
Hello Holger,

Holger Levsen  schrieb am Sa., 27. Okt. 2018, 10:53:

> On Sat, Oct 27, 2018 at 03:08:22AM +0200, Maillist wrote:
> > Unfortunately, with coreboot (assuming you mean a security relevant
> > coreboot), there are none which fit your specs.However, its possible to
> > hack a 13.3 FHD display in an x230.
>
> https://forum.thinkpads.com/viewtopic.php?t=122640 explains how to do
> that. It's not really hard nor expensive.
>

Thanks for the link, I have read this thread before but to me it looks not
like this is an easy operation. But I am also not that engaged in hardware
hacking.
Maybe I post to the thread and ask if this "mod" can be done by someone who
has done this before (x230-display-mod as a service:-)

Anyone from the Qubes Community has done this modification before?

- O

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAJ3yz2vhmYvgLYWhOwFMkshMOvEJxgyj8fCZcaDm71MmFZRFDA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Replacement for Lenovo x230 (coreboot'able + high res)

2018-10-27 Thread 799
Hello Franz,

Franz <169...@gmail.com> schrieb am Sa., 27. Okt. 2018, 07:10:

> (...) An external monitor for x230? (...)
>

I am working in IT Consulting and therefor need to travel.
Most time people complain when I travel by train/public transportation and
bring in 23" external display and start the engine of the  power generator
;-)

am considering to buy a Onyx Boox Max 2 which is e-ink (black and white) to
> save my eyes and is portable, so somebody posted photos of the Onyx
> attached with velcro to the x230.
>

Interesting device, but the reviews mention that display lag is to big to
be used as monitor.

- O

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAJ3yz2sW_P-SgHk24bsT4VxqRsZ2vJhf24xGKFBE0PnSJwbanw%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Replacement for Lenovo x230 (coreboot'able + high res)

2018-10-27 Thread Holger Levsen
On Sat, Oct 27, 2018 at 03:08:22AM +0200, Maillist wrote:
> Unfortunately, with coreboot (assuming you mean a security relevant
> coreboot), there are none which fit your specs.However, its possible to
> hack a 13.3 FHD display in an x230.

https://forum.thinkpads.com/viewtopic.php?t=122640 explains how to do
that. It's not really hard nor expensive.


-- 
cheers,
Holger

---
   holger@(debian|reproducible-builds|layer-acht).org
   PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20181027085350.vkqszjcdeojyihyj%40layer-acht.org.
For more options, visit https://groups.google.com/d/optout.


signature.asc
Description: PGP signature


Re: [qubes-users] Re: Thinkpad X1 Carbon Gen6 suspend/resume issues

2018-10-27 Thread tfm853 via qubes-users
On Saturday, October 27, 2018 at 9:01:23 AM UTC+2, tfm...@googlemail.com wrote:
> On Saturday, October 27, 2018 at 1:00:23 AM UTC+2, Ranguvar wrote:
> > Hyperthreading disable documented here: 
> > https://groups.google.com/forum/m/#!topic/qubes-announce/JEtRYPmG-pAl
> I re-enabled hyperthreading using the boot option 'smt=on'. All the CPU 
> related issues are gone then, including the increased heat.

If I have 'smt=on' but hyperthreading disabled in BIOS, the issues do not 
appear. I don't know if this is security-wise equivalent to 'smt=off'.

I guess I would take the risk for the added performance anyways. Although I 
would have to do some benchmarks first: My old system (Qubes 3.2) has 
hyperthreading disabled too since whenever this update was. I have not noticed 
any performance drops. In fact, I lately was less annoyed by its performance.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/483dd15c-9164-4c4b-b43d-28d40f0c9584%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Re: Thinkpad X1 Carbon Gen6 suspend/resume issues

2018-10-27 Thread tfm853 via qubes-users
On Saturday, October 27, 2018 at 1:00:23 AM UTC+2, Ranguvar wrote:
> I can replicate your CPU temp bug. Mine goes from ~42C on all cores to ~53C. 
> 0% CPU usage, no fans.
> 
> 
> xenpm also errors on two CPUs (1 and 3 for me).
> 
> 
> BIOS v1.31, Hyperthreading on in BIOS
> 
> 
> Hyperthreading disable documented here: 
> https://groups.google.com/forum/m/#!topic/qubes-announce/JEtRYPmG-pAl
> 
> 
> Cannot replicate using Arch with sway or Xorg 1.20.3, 4.18.16-ck kernel.

Thanks alot! This is very helpful.

I re-enabled hyperthreading using the boot option 'smt=on'. All the CPU related 
issues are gone then, including the increased heat.

I hope the option to do that will be retained in the future. Hardened security 
is a great thing, but actually my prime reason for using Qubes is its superior 
organisation and ease to use.

Although I expect the heat issue to be a bug of some kind.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/4cab54ea-b311-4523-9166-c5086e38b93e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.