Re: [qubes-users] Question on creating USB qube

2016-07-28 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA256

On Thu, Jul 28, 2016 at 03:31:12PM -0300, Desobediente wrote:
> What that option means is to not actually create a new "sys-usb" qube to
> handle the USB controllers, but rather use the already existing "sys-net"
> qube to handle the USB controllers.
> 
> Since the "sys-net" qube already handles networking, the option states
> "both networking and USB devices".
> 
> Having a "sys-usb" qube on will probably consume a small amount of
> additional RAM memory, and having "sys-net" handle more things will
> probably open an hypothetical probability of something going wrong in an
> hypothetical future.
> 
> Come to think about it, I have another question: how different would be to
> use USB network cards in the three different scenarios (USB handled by
> dom0, sys-net and sys-usb)?

USB handled in dom0: no way to use it for VM networking

USB handled in sys-net: should be easily accessible using the same
NetworkManager icon

USB handled in sys-usb: possible to use it after some configuration:
One of:
 - assign the device to sys-net using qvm-usb
 - enable NetworkManager sys-usb (in "services" tab in sys-usb settings)
   and assign it as a netvm for sys-firewall

- -- 
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-BEGIN PGP SIGNATURE-
Version: GnuPG v2

iQEcBAEBCAAGBQJXmorcAAoJENuP0xzK19csTDUIAJoctr5bseALRFL0VDfWmSjG
+kjLeCsmhcSZ3tkhw27GH4Au9PMuDlrHjkrTzk0fpg61r7VkM/YuobJn+/3T79TK
GjEgJa1mtUEkGRVtz1S9SyMLiK2kZXE4jIYWmc42auxYmrM/8f5wLg/Md4rFKKIO
50xeSXu9uagfaQp2UZG5gPZxAQ1rEj7RMenwLFE0fB9L1JYusQXyxajAIC8f8zZT
ce/M7ImmGC7B3Ig6QWCgHF4rnsZPZaUXd5UgxFoenEyITn4MP6Ar4aYSmP1fYqSv
Onh3vZvx79K0M+oI0QhtKcmuUbP+jARZQwkyWb4p0TRkfdokVte5LgPOqdCLMcE=
=cE/N
-END PGP SIGNATURE-

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20160728224443.GI32095%40mail-itl.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Question on creating USB qube

2016-07-28 Thread R.B.

On 07/28/2016 08:43 PM, neilhard...@gmail.com wrote:

OK thanks for the explanation.

Let me follow up with another question.

Do I need to create a USB qube in order to take advantage of the VT-D/IOMMU 
protection for my internal WiFi chip... or is sys-net OK in that regard..?



Hi Neil,

In my experience, USB network dongle (either wifi or copper), do not 
seem to work outside the the USB cube. I tried to assign the USB network 
adapter to sys-net, but it failed Since then, I installed 3.2rc1 
with the option of USB and networking in one qube.


You Could try it, but I think you'd need to prevent the network drivers 
from loading in the USB qube somehow.


Greetings,

RB

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/730d826e-bf5c-3e15-8117-b8f936240b5e%40reboli.nl.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Question on creating USB qube

2016-07-28 Thread neilhardley
OK thanks for the explanation.

Let me follow up with another question.

Do I need to create a USB qube in order to take advantage of the VT-D/IOMMU 
protection for my internal WiFi chip... or is sys-net OK in that regard..?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5dc5207a-ac2d-4360-935e-66f8ee07ae21%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Question on creating USB qube

2016-07-28 Thread Desobediente
What that option means is to not actually create a new "sys-usb" qube to
handle the USB controllers, but rather use the already existing "sys-net"
qube to handle the USB controllers.

Since the "sys-net" qube already handles networking, the option states
"both networking and USB devices".

Having a "sys-usb" qube on will probably consume a small amount of
additional RAM memory, and having "sys-net" handle more things will
probably open an hypothetical probability of something going wrong in an
hypothetical future.

Come to think about it, I have another question: how different would be to
use USB network cards in the three different scenarios (USB handled by
dom0, sys-net and sys-usb)?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAF0bz4R2USokm18Mir5AjyPYzasLPRCRq_EoAw_EG8WGoH3CkA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Question on creating USB qube

2016-07-28 Thread neilhardley
I am installing QUBES 3.2 to a new laptop.

With the 1st option:

[X] "Create a USB qube holding all USB controllers (sys-usb) [experimental]"

There is then a 2nd option underneath:

[ ] "Use sys-net qube for both networking and USB devices"

Is it recommended to check the box for the 2nd option or not?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/f839361d-effb-4543-8fd2-8598398c40c7%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.