Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-16 Thread Chris Laprise
On 10/16/20 5:56 AM, Andrew David Wong wrote: On 10/14/20 3:01 AM, Chris Laprise wrote: On 10/11/20 8:58 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Oct 11, 2020 at 06:45:26PM -0500, Andrew David Wong wrote: On 10/11/20 11:16 AM, Marek

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-14 Thread Chris Laprise
ke longer to execute. They also appear to fail more frequently than regular updates. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Go

Re: [qubes-devel] R4.1 some qubes-rpc rules are not working

2020-10-03 Thread Chris Laprise
157]: qt.qpa.xcb: QXcbConnection: XCB error: 3 (BadWindow), sequence: 10683, resource id: 58742628, major code: 18 (ChangeProperty), minor code: 0 Oct 03 11:16:02 dom0 qrexec-policy-daemon[11936]: bash: DEFAULT:QUBESRPC: command not found -- Chris Laprise, tas...@posteo.net https://github.com/tasket ht

Re: [qubes-devel] R4.1 some qubes-rpc rules are not working

2020-10-03 Thread Chris Laprise
get is None or default_target in targets_for_ask Oct 03 10:56:06 dom0 qrexec-policy-daemon[2296]: AssertionError -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message beca

Re: [qubes-devel] R4.1 some qubes-rpc rules are not working

2020-10-03 Thread Chris Laprise
On 10/1/20 11:12 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Sep 28, 2020 at 08:12:48PM -0400, Chris Laprise wrote: There are two separate rpc configurations I tried recently which failed to work: 1. The 'vm-sudo' doc instructions for a sudo

[qubes-devel] R4.1 some qubes-rpc rules are not working

2020-09-28 Thread Chris Laprise
. The manual instructions for sys-usb keyboard proxy do not work with 'ask'... they only work with 'allow'. I'd really like to get both of these security-critical prompts working on Qubes 4.1. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5

Re: [qubes-devel] "Make an Alpha!"

2020-09-24 Thread Chris Laprise
? Thanks... -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from this grou

Re: [qubes-devel] "Make an Alpha!"

2020-09-22 Thread Chris Laprise
On 9/21/20 6:27 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Sep 21, 2020 at 09:18:35AM -0400, Chris Laprise wrote: Chris Laprise: * Allocating a thin lvm pool and then using the plain file pool type Can you expand on what you're trying to do

Re: [qubes-devel] "Make an Alpha!"

2020-09-22 Thread Chris Laprise
On 9/21/20 6:28 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Sep 21, 2020 at 08:18:19AM -0400, Chris Laprise wrote: (BTW, running qubes-builder in fc32 instead of fc30 results in an iso with an invalid grub config). Can you post what exactly

Re: [qubes-devel] "Make an Alpha!"

2020-09-21 Thread Chris Laprise
Chris Laprise: * Allocating a thin lvm pool and then using the plain file pool type Can you expand on what you're trying to do and how it's going wrong? From the 'initial-setup-ks.cfg' file on the 4.1 machine: > %packages > @^qubes-xfce > @qubes-ui And: > %addon org_qubes_os_i

Re: [qubes-devel] "Make an Alpha!"

2020-09-21 Thread Chris Laprise
have suggestions for gathering debug info I'll try them. Chris Laprise: * Allocating a thin lvm pool and then using the plain file pool type Can you expand on what you're trying to do and how it's going wrong? After building the iso and storing it on usb flash, I boot it using additional

Re: [qubes-devel] "Make an Alpha!"

2020-09-20 Thread Chris Laprise
all templates and vm kernels * Allocating a thin lvm pool and then using the plain file pool type * VMs ignoring the selected keyboard layout * Incompatibility with a popular Intel wifi card Those first few are pretty rough. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https

[qubes-devel] Feasibility of modifying Qubes metadata outside Qubes dom0 env

2020-09-10 Thread Chris Laprise
as the key. Thanks in advance... -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubs

Re: [qubes-devel] WIP: Qubes on KVM

2020-08-01 Thread Chris Laprise
://gpuopen.com/ -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from this grou

[qubes-devel] Re: Nvidia driver issue

2020-05-30 Thread Chris Laprise
not help (with either the iGPU or dGPU as the sink) in my case. An "Nvidia Graphics" logo on a computer should serve as a warning to users of open source operating systems. Even Linus Torvalds is visibly angry at that company. -- Chris Laprise, tas...@posteo.net https://github.

Re: [qubes-devel] Thoughts on PGP vs signify and age?

2020-03-19 Thread Chris Laprise
On 3/18/20 2:24 PM, Konstantin Ryabitsev wrote: On Wed, Mar 18, 2020 at 02:16:34PM -0400, Chris Laprise wrote: On 3/18/20 1:48 PM, Konstantin Ryabitsev wrote: Will Qubes transition at some point? I think Qubes should offer signify-style signatures on its released objects, sure. But how

Re: [qubes-devel] Thoughts on PGP vs signify and age?

2020-03-18 Thread Chris Laprise
, and also I think Joanna Rutkowska (although no longer with Qubes) is right to be supportive of the GPG project. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you

Re: [qubes-devel] Shared /home partition

2020-02-28 Thread Chris Laprise
is not meant to hold application data files. They are a security risk if you use them there. And there is no space issue... the dom0 'root' logical volume doesn't occupy any more space than it needs to hold the operating system (bc it exists in the thin pool). -- Chris Laprise, tas...@posteo.net

Re: [qubes-devel] AEM upgrade locks up

2020-01-25 Thread Chris Laprise
On 1/16/20 12:21 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, Jan 15, 2020 at 11:03:44PM -0500, Chris Laprise wrote: Upgrading : anti-evil-maid-4.0.2-1 After 25 minutes nothing has happened. Ctrl-c doesn't stop it so I'll have to reboot

[qubes-devel] AEM upgrade locks up

2020-01-15 Thread Chris Laprise
Upgrading : anti-evil-maid-4.0.2-1 After 25 minutes nothing has happened. Ctrl-c doesn't stop it so I'll have to reboot without completing the dnf transaction... -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3

Re: [qubes-devel] Qubes 4.0.2 severe issue - dom0 kernel crash

2020-01-04 Thread Chris Laprise
it is in such a way that my earlier suggestion would work. :( -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-

Re: [qubes-devel] Qubes 4.0.2 severe issue - dom0 kernel crash

2020-01-04 Thread Chris Laprise
On 1/4/20 9:39 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Jan 04, 2020 at 09:28:45AM -0500, Chris Laprise wrote: Can discards be disabled from the 4.0.2 installer? That could reduce the urgency for a new release. Not easily, besides 'discard

Re: [qubes-devel] Qubes 4.0.2 severe issue - dom0 kernel crash

2020-01-04 Thread Chris Laprise
That could reduce the urgency for a new release. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel" g

[qubes-devel] Certifying AMD based systems

2019-11-14 Thread Chris Laprise
post summarizes my thoughts about why Intel is so problematic (beyond being closed design) that AMD is currently a more responsible choice... https://groups.google.com/d/msgid/qubes-users/85c426f7-7e17-b1ab-87c3-71f92d169955%40posteo.net -- Chris Laprise, tas...@posteo.net https://github.com

Re: [qubes-devel] Gigantic kernel updates taking 25+minutes to dl

2019-09-10 Thread Chris Laprise
On 9/10/19 8:22 PM, Chris Laprise wrote: On 9/10/19 6:43 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Sep 10, 2019 at 06:33:28PM -0400, Chris Laprise wrote: 4.19.36 = 253MB 4.19.43 (vm) = 513MB 4.19.67 (vm) taking >25min to downl

Re: [qubes-devel] Gigantic kernel updates taking 25+minutes to dl

2019-09-10 Thread Chris Laprise
On 9/10/19 6:43 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Sep 10, 2019 at 06:33:28PM -0400, Chris Laprise wrote: 4.19.36 = 253MB 4.19.43 (vm) = 513MB 4.19.67 (vm) taking >25min to download at 120kBytes / sec. What is going on? The si

[qubes-devel] Gigantic kernel updates taking 25+minutes to dl

2019-09-10 Thread Chris Laprise
4.19.36 = 253MB 4.19.43 (vm) = 513MB 4.19.67 (vm) taking >25min to download at 120kBytes / sec. What is going on? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this mess

Re: [qubes-devel] QSB #050: Reinstalling a TemplateVM does not reset the private volume

2019-07-25 Thread Chris Laprise
/QubesOS/qubes-issues/issues/5192 -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubs

Re: [qubes-devel] Backport newer 'thin-provisioning-tools' to dom0?

2019-07-16 Thread Chris Laprise
On 6/28/19 5:29 PM, Chris Laprise wrote: On 6/28/19 3:35 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Jun 28, 2019 at 02:56:46PM -0400, Chris Laprise wrote: Before releasing my lvm backup tool, I thought I'd ask about updating thin-provisioning

Re: [qubes-devel] Backport newer 'thin-provisioning-tools' to dom0?

2019-06-28 Thread Chris Laprise
On 6/28/19 3:35 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Jun 28, 2019 at 02:56:46PM -0400, Chris Laprise wrote: Before releasing my lvm backup tool, I thought I'd ask about updating thin-provisioning-tools package from the rather old 0.5.x

[qubes-devel] Backport newer 'thin-provisioning-tools' to dom0?

2019-06-28 Thread Chris Laprise
with both 4.14 and 4.19 kernels; none of the updated commands have crashed on me. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Goo

[qubes-devel] Python 3.6 in dom0

2019-06-21 Thread Chris Laprise
for general use (what if the user has 3.7?) and the latter leaves me stuck with 3.5 in dom0. Is there some way to convert dom0 to use python 3.6 as the default for 'python3', without breaking Qubes? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2

[qubes-devel] Re: [qubes-users] Fedora 28 has reached EOL

2019-05-30 Thread Chris Laprise
and there are 219 packages to update. 2. Trying to remove thunderbird, dnf wants to remove 67 packages incl. most of qubes*, nftables, salt, tinyproxy. It would be good to be able to remove thunderbird or other large apps without the OS crumbling to pieces. -- Chris Laprise, tas...@posteo.net https

Re: [qubes-devel] Re: ANN: Fast incremental backups project

2019-05-28 Thread Chris Laprise
On 5/28/19 4:31 PM, Mike Keehan wrote: On Mon, 27 May 2019 12:45:15 -0700 (PDT) Ivan Mitev wrote: On Wednesday, 22 May 2019 01:03:44 UTC, qtpie wrote: Chris Laprise: On 12/09/2018 10:38 AM, Chris Laprise wrote: 'Sparsebak' Fast Time Machine-like disk image backups for Qubes OS and Linux

Re: [qubes-devel] Re: ANN: Fast incremental backups project

2019-05-21 Thread Chris Laprise
On 5/21/19 6:24 PM, qtpie wrote: Chris Laprise: On 12/09/2018 10:38 AM, Chris Laprise wrote: 'Sparsebak' Fast Time Machine-like disk image backups for Qubes OS and Linux LVM. And of course, a link to the project :) https://github.com/tasket/sparsebak Have people been using

Re: [qubes-devel] QSB #49: Microarchitectural Data Sampling speculative side channel (XSA-297)

2019-05-16 Thread Chris Laprise
consider recommending a switch to AMD processors as a short-term mitigation against CPU vulnerabilities. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you

Re: [qubes-devel] Possibly dropping support for old qemu-traditional subdomain in R4.1

2019-04-12 Thread Chris Laprise
switching to the new stubdomain and see how it works. Any opinions? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups &q

Re: [qubes-devel] More regular point releases schedule?

2019-02-06 Thread Chris Laprise
a sub-point increment (just as for bug fixes) but with a date indicator also present in all the relevant release and package files. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received

Re: [qubes-devel] Allocating(too fast)fails and triggers OOM-killer before MemTotal reaches AppVM's set Max memory

2019-02-06 Thread Chris Laprise
incurred by swap are used to buy time for qmemman. If I were more familiar with the subject, I might propose a memory allocation method that is synchronous and therefore more deterministic. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2

Re: [qubes-devel] Why is the RAM always gone?

2019-02-03 Thread Chris Laprise
some windows. Even with KDE, 1500MB lets the system run smoothly. Overall, this can make a critical improvement in usability. On an 8GB system, there's a big difference between being able to run 6 appVMs and being able to run 9. -- Chris Laprise, tas...@posteo.net https://github.com/tasket

Re: [qubes-devel] Why is the RAM always gone?

2019-02-03 Thread Chris Laprise
On 2/3/19 7:41 AM, Plex wrote: On Sunday, February 3, 2019 at 10:41:22 AM UTC, Hugo Riebmann wrote: Chris Laprise: I wrote a script to condense the info with a sum of the total amount used: https://github.com/tasket/Qubes-scripts/blob/master/system-stats-xen Thank you! My shell-foo

Re: [qubes-devel] Why is the RAM always gone?

2019-01-30 Thread Chris Laprise
max RAM for dom0 can save a lot of memory but requires editing the "dom0_mem" parameters in /etc/default/grub (if not using UEFI) and then update with the 'dracut' command. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20

Re: [qubes-devel] apt RCE

2019-01-24 Thread Chris Laprise
On 01/23/2019 09:03 AM, unman wrote: On Tue, Jan 22, 2019 at 10:06:01PM -0500, Chris Laprise wrote: I didn't realize, as Ilpo suggested, that I should comment-out the other sources temporarily. That did the trick. deb.debian.org, which you are using, isnt a repository. It's a placeholder

Re: [qubes-devel] apt RCE

2019-01-23 Thread Chris Laprise
to consider. I suppose the latter is relatively easy to update, but the iso not so much. I wouldn't object to a dom0 solution that - at template install time - tests a watchlist of package versions for that OS. This could be touted as a form of VM hardening offered by Qubes. -- Chris Laprise, tas

Re: [qubes-devel] apt RCE

2019-01-22 Thread Chris Laprise
On 01/22/2019 09:51 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Jan 22, 2019 at 09:44:31PM -0500, Chris Laprise wrote: On 01/22/2019 08:49 PM, unman wrote: On Tue, Jan 22, 2019 at 12:57:37PM -0500, Chris Laprise wrote: On 01/22/2019 12:03 PM

Re: [qubes-devel] apt RCE

2019-01-22 Thread Chris Laprise
On 01/22/2019 08:49 PM, unman wrote: On Tue, Jan 22, 2019 at 12:57:37PM -0500, Chris Laprise wrote: On 01/22/2019 12:03 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Jan 22, 2019 at 08:03:01AM -0800, Brendan Hoar wrote: https://justi.cz

Re: [qubes-devel] apt RCE

2019-01-22 Thread Chris Laprise
that Debian's temporary update instructions from their security bulletin do not work in the Qubes template. So we are missing a straightforward resolution that Qubes users can follow. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A

Re: [qubes-devel] ANN: Fast incremental backups project

2019-01-01 Thread Chris Laprise
On 12/31/2018 08:49 AM, Brendan Hoar wrote: On Saturday, December 29, 2018 at 2:30:12 PM UTC-5, Chris Laprise wrote: Also note that we'd like to have at least some level of hiding metadata - - like VM names (leaked through file names). I have an idea for a relatively simple obfuscation layer

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-29 Thread Chris Laprise
On 12/22/2018 08:48 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Dec 21, 2018 at 08:39:43AM -0500, Chris Laprise wrote: On 12/20/2018 09:40 PM, Marek Marczykowski-Górecki wrote: Thanks for doing this! I haven't really looked at the code, but I

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-21 Thread Chris Laprise
ed handling of remote repositories (like duplicity) Actually this is one of Sparsebak's strong points... very low interactivity during remote operations. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 18

[qubes-devel] VM settings extraction & restoration

2018-12-20 Thread Chris Laprise
Is there a general procedure for assembling Qubes VM configuration data so that a complete backup and restoration of VM settings can be neatly executed? Related: https://github.com/tasket/sparsebak/issues/18 -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-13 Thread Chris Laprise
On 12/13/2018 02:33 PM, Chris Laprise wrote: On 12/12/2018 05:12 PM, Steve Coleman wrote: On 12/12/18 2:41 PM, Chris Laprise wrote: On 12/12/2018 09:11 AM, Steve Coleman wrote: On 12/12/18 8:13 AM, Chris Laprise wrote: A fix has been pushed to master (alpha2). I ran this new version

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-13 Thread Chris Laprise
On 12/12/2018 05:12 PM, Steve Coleman wrote: On 12/12/18 2:41 PM, Chris Laprise wrote: On 12/12/2018 09:11 AM, Steve Coleman wrote: On 12/12/18 8:13 AM, Chris Laprise wrote: A fix has been pushed to master (alpha2). I ran this new version and the first time it gave another error. Second

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-12 Thread Chris Laprise
On 12/12/2018 09:11 AM, Steve Coleman wrote: On 12/12/18 8:13 AM, Chris Laprise wrote: A fix has been pushed to master (alpha2). I ran this new version and the first time it gave another error. Second time the same error, third time trying to capture a logfile it ran but was incomplete

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-12 Thread Chris Laprise
On 12/11/2018 02:20 PM, Ivan Mitev wrote: On 12/11/18 8:46 PM, Chris Laprise wrote: On 12/11/2018 11:19 AM, Ivan Mitev wrote: On 12/11/18 5:20 PM, Steve Coleman wrote: I was attempting to "send" all my VM's private sections to a drive mounted on sys-usb, and I seem t

Re: [qubes-devel] RAM troubles

2018-12-12 Thread Chris Laprise
timings are incorrectly set. Check the mfg specs carefully to make sure it supports your model of laptop; if it does, then check to see if your BIOS has an update available. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-11 Thread Chris Laprise
e the error? I also posted an update in the 'new' branch that will print out the relevant values if/when the error occurs: https://github.com/tasket/sparsebak/tree/new Thanks! -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-11 Thread Chris Laprise
On 12/10/2018 08:27 PM, Andrew David Wong wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 12/10/18 11:57 AM, Chris Laprise wrote: On 12/10/2018 05:23 AM, Ivan Mitev wrote: That's really great work. On 12/9/18 5:38 PM, Chris Laprise wrote: Status - Alpha version -- Can do

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-11 Thread Chris Laprise
On 12/10/2018 09:42 PM, Outback Dingo wrote: On Tue, Dec 11, 2018 at 12:57 AM Chris Laprise wrote: On 12/10/2018 05:23 AM, Ivan Mitev wrote: That's really great work. On 12/9/18 5:38 PM, Chris Laprise wrote: Status - Alpha version -- Can do full or incremental backups of Linux thin

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-10 Thread Chris Laprise
On 12/10/2018 05:23 AM, Ivan Mitev wrote: That's really great work. On 12/9/18 5:38 PM, Chris Laprise wrote: Status - Alpha version -- Can do full or incremental backups of Linux thin-provisioned LVM to local dom0 or VM filesystems or via ssh, as well as simple volume retrieval

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-09 Thread Chris Laprise
On 12/09/2018 10:38 AM, Chris Laprise wrote: 'Sparsebak' Fast Time Machine-like disk image backups for Qubes OS and Linux LVM. And of course, a link to the project :) https://github.com/tasket/sparsebak -- Chris Laprise, tas...@posteo.net https://github.com/tasket https

[qubes-devel] ANN: Fast incremental backups project

2018-12-09 Thread Chris Laprise
is the name: I don't really like the current working title and would appreciate your suggestions and PRs on this and many other issues! -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You

Re: [qubes-devel] Dropping support for old templates

2018-12-01 Thread Chris Laprise
On 11/30/2018 08:16 PM, unman wrote: On Fri, Nov 30, 2018 at 07:25:15PM -0500, Chris Laprise wrote: On 11/30/2018 06:06 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 [moved discussion from ticket #2065] On Fri, Nov 30, 2018 at 11:44:21AM +, Patrick

Re: [qubes-devel] Dropping support for old templates

2018-11-30 Thread Chris Laprise
at said, I don't think long-term Debian support should necessarily apply to Whonix, which is its own distro in a sense. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this messa

Re: [qubes-devel] Where does Qubes-UX fit in?

2018-11-20 Thread Chris Laprise
ld 3.x UI options will be a gradual process. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel" group.

[qubes-devel] Re: [qubes-users] nftables vs iptables

2018-10-10 Thread Chris Laprise
:56 AM, mfreemon wrote: On 10/2/18 2:25 AM, Ivan Mitev wrote: On 10/2/18 1:32 AM, Chris Laprise wrote: On 10/01/2018 05:48 PM, mfreemon wrote: On 1/11/18 3:01 PM, Chris Laprise wrote:     > On 01/10/2018 03:47 PM, Connor Page wrote:     >> The official templates use nftables so shouldn’t

Re: [qubes-devel] qubes-builder stops with error

2018-09-20 Thread Chris Laprise
On 09/20/2018 10:30 AM, unman wrote: I saw that yesterday and thought it was my meddling. It's a new bug - will you report it? OK, its https://github.com/QubesOS/qubes-issues/issues/4327 -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2

Re: [qubes-devel] qubes-builder stops with error

2018-09-20 Thread Chris Laprise
akefile:217: meta-packages-vm] Error 1 -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel" group.

[qubes-devel] qubes-builder stops with error

2018-09-19 Thread Chris Laprise
hare/perl5/vendor_perl/Digest.pm line 44. make[2]: *** [/home/user/qubes-builder/qubes-src/builder-debian/Makefile.debian:173: dist-build-dep] Error 2 make[1]: *** [Makefile.generic:177: packages] Error 1 make: *** [Makefile:217: vmm-xen-vm] Error 1 -- Chris Laprise, tas...@posteo.net

Re: [qubes-devel] Total removal of swap files from qubes as an installation option

2018-08-21 Thread Chris Laprise
audience monitoring TVs, there is reason to distrust their products based on their motives and lack of respect for people's privacy. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received

Re: [qubes-devel] Whonix Testers Wanted!

2018-08-16 Thread Chris Laprise
far. Only quirk that I also have with stable is when I shutdown a browser VM with my hotkey config (it runs a script that quits firefox + thunderbird in the foreground VM, then does qvm-shutdown on it) there is a popup saying "Error: Failed to start Tor Browser". -- Chris La

Re: [qubes-devel] How to use VPN for encrypt traffic from Tor exit node of Whonix?

2018-05-02 Thread Chris Laprise
ts for TCP. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from this grou

Re: [qubes-devel] IP forwarding is on while qubes-firewall starts

2018-04-19 Thread Chris Laprise
On 04/19/2018 10:59 PM, Chris Laprise wrote: On 04/19/2018 10:54 PM, Chris Laprise wrote: On 04/19/2018 09:10 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Apr 19, 2018 at 08:29:17PM -0400, Chris Laprise wrote: A departure from the R3.x

Re: [qubes-devel] IP forwarding is on while qubes-firewall starts

2018-04-19 Thread Chris Laprise
On 04/19/2018 10:54 PM, Chris Laprise wrote: On 04/19/2018 09:10 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Apr 19, 2018 at 08:29:17PM -0400, Chris Laprise wrote: A departure from the R3.x behavior that I think may compromise network security

Re: [qubes-devel] IP forwarding is on while qubes-firewall starts

2018-04-19 Thread Chris Laprise
On 04/19/2018 09:10 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Apr 19, 2018 at 08:29:17PM -0400, Chris Laprise wrote: A departure from the R3.x behavior that I think may compromise network security is that in R4.0 proxyVMs /proc/sys/net/ipv4

[qubes-devel] IP forwarding is on while qubes-firewall starts

2018-04-19 Thread Chris Laprise
be a patch (ex: /etc/sysctl.conf) to have the initial VM forwarding state at '0' until qubes-firewall finishes initializing. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message

Re: [qubes-devel] Offering salt help

2018-04-19 Thread Chris Laprise
M sudo/pam configuration. Also explore if its useful for configuring VPNs. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qub

[qubes-devel] Moving cache dirs out of /dev/xvdb

2018-03-30 Thread Chris Laprise
to prefer block-device backups. So having a "cache" class of storage volume for each VM makes sense from this perspective. I just wanted to post this idea to explore whether its worth exploring. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP:

Re: [qubes-devel] Re: Firewall fixes not in 4.0rc5 stable repo

2018-03-09 Thread Chris Laprise
On 03/09/2018 04:43 PM, Marek Marczykowski-Górecki wrote: On Fri, Mar 09, 2018 at 04:26:26PM -0500, Chris Laprise wrote: Per issues #3260 and #3503. The commits are approaching one month old but still in current-testing. I thought they'd make it to rc5 stable. Templates in rc4 have qubes-core

[qubes-devel] Firewall fixes not in 4.0rc5 stable repo

2018-03-09 Thread Chris Laprise
Per issues #3260 and #3503. The commits are approaching one month old but still in current-testing. I thought they'd make it to rc5 stable. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You

Re: [qubes-devel] Permission denied when using Qubes().domains

2018-03-06 Thread Chris Laprise
On 03/04/2018 09:30 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Mar 04, 2018 at 05:46:39AM -0500, Chris Laprise wrote: On 02/21/2018 06:20 AM, Wojtek Porczyk wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Feb 20, 2018 at 10:45

Re: [qubes-devel] Permission denied when using Qubes().domains

2018-03-04 Thread Chris Laprise
On 02/21/2018 06:20 AM, Wojtek Porczyk wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Feb 20, 2018 at 10:45:55PM -0500, Chris Laprise wrote: Using python3 in dom0, trying to access qubes.Qubes().domains results in the following error: /dev/mapper/control: open failed

[qubes-devel] Permission denied when using Qubes().domains

2018-02-20 Thread Chris Laprise
python3' instead. I don't know if this is considered normal behavior or a bug, as I would normally expect admin objects to be accessible with normal user privs. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106

Re: [qubes-devel] qubes-firewall script error handling

2018-02-19 Thread Chris Laprise
On 02/18/2018 06:30 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Feb 18, 2018 at 01:10:44PM -0500, Chris Laprise wrote: I'm thinking about posting a PR to have qubes-firewall raise errors whenever a firewall script from qubes-firewall-user

[qubes-devel] qubes-firewall script error handling

2018-02-18 Thread Chris Laprise
or "exit 1" etc. so the service goes into a failed state. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups

Re: [qubes-devel] [Fwd: Issue #3553: Debian based UpdateVM does not support --action=list or reinstall]

2018-02-10 Thread Chris Laprise
support, so I think the only answer is for the user to keep a Fedora-based VM on hand if they wish to do anything more with packages in dom0 than simple updates. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106

Re: [qubes-devel] R4-rc3 testing: VM settings attribute error

2018-01-20 Thread Chris Laprise
On 01/20/2018 10:41 AM, 'MirrorWay' via qubes-devel wrote: Fix and workaround in https://github.com/QubesOS/qubes-issues/issues/3475 Thanks. Yes, my default_dispvm was set to None. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E

Re: [qubes-devel] R4.0-rc4 installation image considerations

2018-01-20 Thread Chris Laprise
rent debian template as debian-9-minimal, but don't include it) OTOH, stating that a dual-layer DVD is required is much simpler, and DL burners are pretty common. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3

[qubes-devel] R4-rc3 testing: VM settings attribute error

2018-01-20 Thread Chris Laprise
) func: main line no.: 1128 file: /usr/lib/python3.5/site-packages/qubesmanager/settings.py line: load_entry_point('qubesmanager==4.0.11', 'console_scripts', 'qubes-vm-settings')() func: line no.: 9 file: /usr/bin/qubes-vm-settings -- Chris Laprise, tas...@posteo.net https://github.com

Re: [qubes-devel] Upgrade instructions for R3.2 and QSB37 patches

2018-01-18 Thread Chris Laprise
this should be commuted to mean "latest release from the 3.x series". You could release an upgrade as either 3.3 or 3.2.5 for example, signifying a large bug fix. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB

Re: [qubes-devel] Re: Script execute bit changed in testing (R4 guest)

2017-12-31 Thread Chris Laprise
On 12/31/2017 07:04 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Dec 31, 2017 at 06:24:51AM -0500, Chris Laprise wrote: When creating new net-providing VMs the default (unused) scripts in /rw/config normally do not have +x set. But after

[qubes-devel] Script execute bit changed in testing (R4 guest)

2017-12-31 Thread Chris Laprise
be overwritten. Shouldn't these default files stay as -x ? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel&q

Re: [qubes-devel] Updates of qubes packages for VMs

2017-12-28 Thread Chris Laprise
bes-issues/issues/2063 -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from

Re: [qubes-devel] Any chance of moving dom0 to F26 for 4.0 final release

2017-12-13 Thread Chris Laprise
essential component is missing for vpn and haven't had time to track it down. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google

[qubes-devel] Re: Fedora-related help

2017-12-13 Thread Chris Laprise
d also like to mention that Fedora's version of tboot is very outdated (from 2014). Qubes uses this for the anti-evil-maid feature: https://sourceforge.net/projects/tboot/files/?source=navbar -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C

Re: [qubes-devel] Need admin api advice

2017-12-01 Thread Chris Laprise
On 11/26/2017 05:56 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Nov 26, 2017 at 05:17:26PM -0500, Chris Laprise wrote: I'm trying to fix issue #3303 (inability to use --verify-only with qvm-backup-restore) but to do that I need to supply vm

Re: [qubes-devel] Re: (trying to avoid) unpacking before checking signatures

2017-11-11 Thread Chris Laprise
On 11/11/2017 06:11 PM, Jean-Philippe Ouellet wrote: On Sat, Nov 11, 2017 at 5:54 PM, Chris Laprise <tas...@posteo.net> wrote: On 11/08/2017 10:55 PM, Jean-Philippe Ouellet wrote: On Wed, Nov 8, 2017 at 10:51 PM, Jean-Philippe Ouellet <j...@vt.edu> wrote: Hello, The way

[qubes-devel] R4.0 policy for rootfs discard/trim?

2017-11-02 Thread Chris Laprise
usage in check? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from

Re: [qubes-devel] Need clarification for R4 qubes-firewall cycles

2017-10-24 Thread Chris Laprise
On 10/24/17 07:36, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Oct 24, 2017 at 01:02:53AM -0400, Chris Laprise wrote: In trying to adapt VPN scripts to Qubes R4.0 I've found the qubes-firewall-user-script has been renamed to qubes-ip-change-hook

[qubes-devel] Need clarification for R4 qubes-firewall cycles

2017-10-23 Thread Chris Laprise
to modify iptables before forwarding is enabled at startup, and subsequently during normal runtime? Thanks! -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you

  1   2   >