Re: [qubes-devel] Introducing: Qubes Video Companion v1.0

2021-04-21 Thread Marek Marczykowski-Górecki
ue) because Mozilla has been a great supporter of Qubes with the big > grant they gave so it's the least we could do as well as to not put > Firefox at a disadvantage. Yes, having this in community repo would be fantastic! In fact, I'd even consider adding it into the main repo and have it inst

Re: [qubes-devel] [qvm-backup-restore] Why --rename-conflicting modifies restored VM name and not the old one?

2021-04-08 Thread Marek Marczykowski-Górecki
ata (VM settings etc) - reverting to older revision is not reversible (you cannot switch back and forth) - you cannot start both old and new versions at the same time (to copy data between them for example) - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN PG

[qubes-devel] Re: Vagrant for generating VMs

2021-04-03 Thread Marek Marczykowski-Górecki
alt is enough? 2. Is Vagrant the right too for the job? If we'd go in a direction like this, I'd strongly prefer to re-use some existing well known tool. Integrating anything into our custom qubes-builder + template-builder has quite high contributor entry barrier. - -- Best Rega

Re: [qubes-devel] [GSoC 2021] Project idea: Simplified external port forwarding and automatic NAT traversal

2021-03-23 Thread Marek Marczykowski-Górecki
inputs. > > > > > >> On 2/17/21 7:27 PM, Marek Marczykowski-Górecki wrote: > >>> > >>> Since some time there is an easier way: > >>> https://www.qubes-os.org/doc/firewall/#opening-a-single-tcp-port-to-other-network-isolated

Re: [qubes-devel] Cleanup on qubes file server (bruschetta)

2021-03-20 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Mar 20, 2021 at 04:20:20PM -0700, Andrew David Wong wrote: > On 3/20/21 12:09 PM, Frédéric Pierret wrote: > > > > > > Le 3/20/21 à 1:42 PM, Marek Marczykowski-Górecki a écrit : > > > On Sat, Mar 20, 2021

Re: [qubes-devel] Cleanup on qubes file server (bruschetta)

2021-03-20 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Mar 20, 2021 at 09:38:19AM +0100, Frédéric Pierret wrote: > > > Le 3/20/21 à 3:20 AM, Marek Marczykowski-Górecki a écrit : > > Hi, > > > > I want to do a little cleanup on the server, to make more room

[qubes-devel] Cleanup on qubes file server (bruschetta)

2021-03-19 Thread Marek Marczykowski-Górecki
reason to keep them online, on the same server, under same URL? Note this content is also mirrored, so removing it from here will also reduce storage usage on all the mirrors. [1] https://www.qubes-os.org/statistics/ - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN

Re: [qubes-devel] broken dom0 updates, shall I report this at qubes-issues?

2021-03-19 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Mar 19, 2021 at 03:07:48PM -0500, Sven Semmler wrote: > On 3/19/21 2:03 PM, Marek Marczykowski-Górecki wrote: > > Are you sure you don't have security-testing or current-testing > > enabled? Those packages are currently onl

Re: [qubes-devel] broken dom0 updates, shall I report this at qubes-issues?

2021-03-19 Thread Marek Marczykowski-Górecki
I've fixed it now: https://github.com/QubesOS/updates-status/issues/2385 You can retry with `qubes-dom0-update --refresh` - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAmBU9XwACgkQ24/THMrX 1yxt8QgAg1

Re: [qubes-devel] Google Summer of Code - Gnome dom0 project

2021-03-16 Thread Marek Marczykowski-Górecki
ly - for example many of the hardware settings like power management). But I don't think you need to worry about it in practice. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN PGP SIGNATURE- iQEyBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAmBQ6v0ACgkQ24/THMrX

Re: [qubes-devel] Contributing a SaltStack module for qvm-appmenus

2021-03-14 Thread Marek Marczykowski-Górecki
here: https://github.com/QubesOS/qubes-desktop-linux-common/tree/master/qubesappmenus I don't think you'll need to modify it or import directly, but it may be helpful to clarify some details. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN PGP SIGNATURE

Re: [qubes-devel] Contributing to Live USB and Wayland || Rachitt Shah

2021-03-11 Thread Marek Marczykowski-Górecki
y requirements. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAmBKP0wACgkQ24/THMrX 1yyVQQf/S3Dm6G/1cgnySbiQVejeau5XKkGtN4tN8nADs/JlzpLOUkfgD+Prfeyw CfAYpbdtxfxoNmt9RP9Wq43U/jBFczwuK1EeodYJ4GvcSl5N7

Re: [qubes-devel] Fwd: qrexec_timeout does not truly accept 3600

2021-03-10 Thread Marek Marczykowski-Górecki
s not honored > > How can i get by this so this one VM can do finish its upgrade before > forcibly rebooted? > - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAmBJZz0ACgkQ24/THMrX 1yyEowf9EGwsC

Re: [qubes-devel] Relation between qubes-core-dom0 and other qubes- packages

2021-03-07 Thread Marek Marczykowski-Górecki
os.org/doc/version-scheme/, but indeed the relation to specific packages versions is not that clear there. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAmBFUqQACgkQ24/THMrX 1yz+DQf+NMqNn

Re: [qubes-devel] Xen exploit mitigations

2021-03-02 Thread Marek Marczykowski-Górecki
n (PV must die first, at the very least). But it does use some other mitigations like SMAP/SMEP. And also some of the more complex parts like instruction emulator are integrated with fuzzy testing. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab -BEGIN PGP SIGNATURE--

Re: [qubes-devel] [GSoC 2021] Project idea: Simplified external port forwarding and automatic NAT traversal

2021-02-17 Thread Marek Marczykowski-Górecki
tps://www.reddit.com/r/Qubes/comments/8cb57i/how_to_achieve_qube_to_qube_communication_port/ > [3] - https://github.com/QubesOS/qubes-issues/issues/6225 > [4] - https://git.lsd.cat/g/thinkpad-coreboot-qubes > [5] - https://lsd.cat > - -- Best Regards, Marek Marczyko

[qubes-devel] Re: Help me test fixes for Intel IGD graphical artifacts on Qubes R4.0

2021-01-15 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Jan 16, 2021 at 01:49:25AM +, Jinoh Kang wrote: > On 1/15/21 8:06 PM, Marek Marczykowski-Górecki wrote: > > On Fri, Jan 15, 2021 at 05:29:43PM +, Jinoh Kang wrote: > >> Is qubes-xorg-x11-drv-intel an option? Upstre

[qubes-devel] Re: Help me test fixes for Intel IGD graphical artifacts on Qubes R4.0

2021-01-15 Thread Marek Marczykowski-Górecki
apshot. We do backport this package from newer Fedora already: https://github.com/QubesOS/qubes-linux-dom0-updates But I would prefer to get it upstream anyway (and then possibly build xorg-x11-drv-intel from newer git snapshot). - -- Best Regards, Marek Marczykowski-Górecki Invisible Thin

[qubes-devel] Re: Help me test fixes for Intel IGD graphical artifacts on Qubes R4.0

2021-01-13 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, Jan 13, 2021 at 01:21:51PM +, Jinoh Kang wrote: > On 1/11/21 11:03 PM, Marek Marczykowski-Górecki wrote: > > So, I can confirm the (fixed) 5.10 patch also improves the situation. > > Sounds good. Thanks for testing!

[qubes-devel] Re: Help me test fixes for Intel IGD graphical artifacts on Qubes R4.0

2021-01-11 Thread Marek Marczykowski-Górecki
llow-up patches and give some feedback here. So, I can confirm the (fixed) 5.10 patch also improves the situation. Have you sent it upstream? I do consider including it in our standard kernel package, but I'd like to see i915 driver maintainer opinion first. - -- Best Regards, Marek Marczykows

[qubes-devel] Re: [PATCH v5.10] drm/i915/userptr: detect un-GUP-able pages early

2021-01-10 Thread Marek Marczykowski-Górecki
const char *type, > diff --git a/drivers/gpu/drm/i915/i915_params.h > b/drivers/gpu/drm/i915/i915_params.h > index 330c03e2b4f7..1169a610a73c 100644 > --- a/drivers/gpu/drm/i915/i915_params.h > +++ b/drivers/gpu/drm/i915/i915_params.h > @@ -79,6 +79,7 @@ struct drm_printer; >

Re: [qubes-devel] Re: msi pci pass-through error with new Qualcomm AX500

2021-01-10 Thread Marek Marczykowski-Górecki
hat it's emulated (emu_mask) which means qemu provides own values instead of passing them from the hardware and the values for those 3 bits are 0 (init_val). I'm not sure how hard would be implementing multi-vector support here, but it's clearly not there. [1] https://github.com/qemu/qemu/blob/master/hw/xen/xen_p

Re: [qubes-devel] Re: Qubes Canary 025

2020-12-12 Thread Marek Marczykowski-Górecki
breaks detached signatures, but not the inline ones. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX

[qubes-devel] Re: [QubesOS/qubes-issues] Efficient compiled binary policy format (#6266)

2020-12-07 Thread Marek Marczykowski-Górecki
. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl/OkYIACgkQ24/THMrX 1yyv3Qf/dlfOvyjyIdPL05K

Re: [qubes-devel] CPUID Spoofing for GPU Passthrough - libxl error

2020-12-02 Thread Marek Marczykowski-Górecki
nd adding INCREMENT_DEVEL_VERSIONS=1 to your builder.conf, so that your build will automatically get higher version and avoid having multiple different binaries with the same version. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people nor

Re: [qubes-devel] Someone should port this RDP Windows windower thing for Qubes

2020-11-30 Thread Marek Marczykowski-Górecki
reverse engineering some parts), in addition to development similar to the second option. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP

Re: [qubes-devel] [GSoD] Progress this week, plans for next week

2020-11-14 Thread Marek Marczykowski-Górecki
>- Application Troubleshooting >- Tails Troubleshooting > > > Thanks for reading. > Have a great weekend. > - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting su

Re: [qubes-devel] Travis-CI changes

2020-11-13 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Nov 13, 2020 at 12:35:55PM +0100, Wojtek Porczyk wrote: > On Thu, Nov 12, 2020 at 11:25:16PM -0800, Andrew David Wong wrote: > > On 11/12/20 1:39 PM, Demi M. Obenour wrote: > > > On 11/12/20 2:56 PM, Marek Marczyko

[qubes-devel] Travis-CI changes

2020-11-12 Thread Marek Marczykowski-Górecki
to do in rush. [1] https://blog.travis-ci.com/2020-11-02-travis-ci-new-billing [2] https://www.qubes-os.org/news/2020/10/05/new-gentoo-templates-and-maintenance-infrastructure/ - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people

[qubes-devel] QSB #61 Information leak via power sidechannel (XSA-351)

2020-11-11 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Dear Qubes Community, We have just published Qubes Security Bulletin (QSB) #61: Information leak via power sidechannel (XSA-351). The text of this QSB is reproduced below. This QSB and its accompanying signatures will always be available in the

Re: [qubes-devel] This week's progress, next week's plans

2020-11-08 Thread Marek Marczykowski-Górecki
Those may be severely outdated. Check git log for them and correlate with Qubes version at that time. At the very least add an info to which version it was applicable. >- Troubleshooting other hardware issues - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it mes

Re: [qubes-devel] Contributing with PGP key servers down?

2020-10-28 Thread Marek Marczykowski-Górecki
/github.com/username.gpg. > > This returns the key as-is. Nice find! This helps a lot. We still want to build a cache, so we can verify signatures even after the key is removed from github (or account deleted etc), but this method can be used to reliably populate that cache. - -- Best

Re: [qubes-devel] Contributing with PGP key servers down?

2020-10-28 Thread Marek Marczykowski-Górecki
key there is more elaborate (requires email confirmation). Any other ideas? - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBC

Re: [qubes-devel] [GSoD] Progress, next steps

2020-10-24 Thread Marek Marczykowski-Górecki
relevant > content has either been placed under "Suspend/Resume Troubleshooting" or > "PCI Troubleshooting". Sounds ok. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-pos

Re: [qubes-devel] Missing kernel-qubes-vm rpm from self-built 4.1 alpha iso

2020-10-20 Thread Marek Marczykowski-Górecki
l instructions. > > Any thoughts? Anyone else seeing this? My build machine is a bit slow, so > I'll try moving *dummy-psu* and *dummy-backlight* above > *linux-template-builder* and see if that fixes issue #1 and report back > some time tomorrow. I think that's it. I've just move

Re: [qubes-devel] [GSoD] Progress this week, Plans for next week

2020-10-18 Thread Marek Marczykowski-Górecki
t;- Performance troubleshooting >- Media troubleshooting Sounds good! - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such

Re: [qubes-devel] "Make an Alpha!"

2020-10-14 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Sep 20, 2020 at 08:03:31PM +0200, Marek Marczykowski-Górecki wrote: > On Sun, Sep 20, 2020 at 05:33:26PM +, Rusty Bird wrote: > > Marek, the masses are chanting it!! > > https://www.youtube.com/watch?v=sq5g-V63Q30=151

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-11 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Oct 11, 2020 at 06:45:26PM -0500, Andrew David Wong wrote: > On 10/11/20 11:16 AM, Marek Marczykowski-Górecki wrote: > > On Sat, Oct 10, 2020 at 09:50:00PM -0500, Andrew David Wong wrote: > > > I still upgrade dom0 and

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-11 Thread Marek Marczykowski-Górecki
to 1) --targets=vm1,vm2,... - limit to specific VMs, instead of all the templates (use instead of --templates --standalones) --show-output - show update summary instead of just OK/FAIL For other options see qubesctl --help - -- Best Regards, Marek Marczykowski-Górecki Invisible

Re: [qubes-devel] [GSoD] Progress and next steps

2020-10-10 Thread Marek Marczykowski-Górecki
report/discussion where the particular issue is analysed (if available) - - this will give more context in case of similar but not exactly the same problem. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in w

Re: [qubes-devel] R4.1 some qubes-rpc rules are not working

2020-10-03 Thread Marek Marczykowski-Górecki
et > is None or default_target in targets_for_ask > Oct 03 10:56:06 dom0 qrexec-policy-daemon[2296]: AssertionError This looks like a bug in dom0 vs @adminvm processing. dom0 is translated to @adminvm in some places but not others... - -- Best Regards, Marek Marczykowski-Górecki Invisi

Re: [qubes-devel] R4.1 some qubes-rpc rules are not working

2020-10-01 Thread Marek Marczykowski-Górecki
l in dom0 and observe qrexec-related messages. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/T

Re: [qubes-devel] "Make an Alpha!"

2020-09-21 Thread Marek Marczykowski-Górecki
is run in a chroot environment that shouldn't depend on the outside distribution... - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIG

Re: [qubes-devel] "Make an Alpha!"

2020-09-21 Thread Marek Marczykowski-Górecki
t; > lvm_pool qubes_dom0/vm-pool > > %end > > Output of 'qvm-pool': > > NAME DRIVER > > varlibqubes file > > linux-kernel linux-kernel > - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which

Re: [qubes-devel] "Make an Alpha!"

2020-09-20 Thread Marek Marczykowski-Górecki
eas, perhaps even bisecting Xen between 4.13 and 4.14 would work. > * > https://github.com/kdave/btrfs-progs/commit/0ff7a9b5210723bd4ad0d9d78dbbb18ee8fdd2b1 [2] https://github.com/QubesOS/qubes-issues/issues/6066 - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Becaus

Re: [qubes-devel] Feasibility of modifying Qubes metadata outside Qubes dom0 env

2020-09-10 Thread Marek Marczykowski-Górecki
ing - typos, broken references between VMs etc will prevent qubesd to start. And since you're probably going to modify storage, be sure to keep metadata (volume names, sizes etc) in sync. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in whic

[qubes-devel] Re: [GSoC] Next Steps

2020-08-26 Thread Marek Marczykowski-Górecki
ends very soon (final report to be submitted this week), I'm quite positive the core part is already in a good shape. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing?

Re: [qubes-devel] Take a snapshot of the Qube's memory

2020-08-12 Thread Marek Marczykowski-Górecki
his in Qubes? > > Thank you in advance! You can use `virsh -c xen dump` or `xl dump-core`. It may be good to pause the qube first. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-postin

Re: [qubes-devel] Linux UEFI IOMMU changes

2020-08-01 Thread Marek Marczykowski-Górecki
tion against DMA attacks. This sounds like a question for xen-devel ML instead. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCA

Re: [qubes-devel] WIP: Qubes on KVM

2020-08-01 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Aug 01, 2020 at 11:32:36AM -0400, Demi M. Obenour wrote: > On 2020-08-01 07:59, Marek Marczykowski-Górecki wrote: > > On Fri, Jul 31, 2020 at 02:17:05PM -0700, Jason M wrote: > >> I then looked into alternatives to p

Re: [qubes-devel] WIP: Qubes on KVM

2020-08-01 Thread Marek Marczykowski-Górecki
libvirt uses the number of processors available (make -j32 V=1). It > will > build without errors if I generate a '.rpmmacros' file containing > '%_smp_mflags' -j10' to the 'chroot-dom0-fc32/home/user' directory. > Just > wondering is

Re: [qubes-devel] Signed repository metadata and untrusted templates

2020-07-26 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Jul 26, 2020 at 09:03:35PM -0400, Demi M. Obenour wrote: > On 2020-07-26 20:31, Marek Marczykowski-Górecki wrote: > > On Sun, Jul 26, 2020 at 06:59:02PM -0400, Demi M. Obenour wrote: > >> When looking at recent posts about

Re: [qubes-devel] Signed repository metadata and untrusted templates

2020-07-26 Thread Marek Marczykowski-Górecki
tall such package with the new qvm-template directly in dom0, but for added protection, it is also possible to use that tool outside of dom0 (given proper Admin API permissions). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people

Re: [qubes-devel] Semiproof 4.1

2020-07-25 Thread Marek Marczykowski-Górecki
(in most cases - all of them). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl

[qubes-devel] Non trial update on Qubes 4.1 - garcon package conflict

2020-07-15 Thread Marek Marczykowski-Górecki
ink we've tried every sensible set of dependencies and dnf options: https://github.com/QubesOS/qubes-desktop-linux-xfce4/pull/21#discussion_r447384248 - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is

[qubes-devel] Re: new issue template "support / question"

2020-07-13 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, May 23, 2020 at 11:16:13AM -0500, Andrew David Wong wrote: > On 2020-05-23 7:48 AM, Marek Marczykowski-Górecki wrote: > > Hi Andrew, > > > > Recently I've stumbled over an idea for issue template: > > https:/

[qubes-devel] Re: Proposal For GSoD 2020

2020-07-09 Thread Marek Marczykowski-Górecki
od ends both for us and for Google (August 16). So, there is quite a bit of time until that: https://developers.google.com/season-of-docs/docs/timeline > Thanks > Sarvottam Kumar > > [1] > https://docs.google.com/document/d/18MvrZ3n4BAOXVsVl-i0petYQCKymrmP3VHExeoFoYEc/edit?usp=sharin

Re: [qubes-devel] [GSoC] Template Manager: Interactions w/ Repos

2020-07-08 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, Jul 08, 2020 at 06:57:05PM +, WillyPillow wrote: > On Tuesday, July 7, 2020 8:57 AM, Marek Marczykowski-Górecki > wrote: > > Perhaps a better solution would be to create new separate package with > > template repo

Re: [qubes-devel] WIP: Nvidia drivers and cuda within VM

2020-07-08 Thread Marek Marczykowski-Górecki
oject.org/docs/unstable-staging/features/dom0less.html > <http://xenbits.xenproject.org/docs/unstable-staging/features/dom0less.html> > [3] https://elinux.org/images/f/f7/Dom0less_-_ELC_2019.pdf > [4] https://www.denx.de/wiki/U-Boot/X86 > <https://www.denx.de/wiki/U-Boot/X8

Re: [qubes-devel] [GSoC] Template Manager: Interactions w/ Repos

2020-07-06 Thread Marek Marczykowski-Górecki
d enough for this use case. If you want to manage templates on Qubes 4.1, use VM with packages from Qubes 4.1. > [^1]: Unfortunately this also means that I'm a bit behind on my original > schedule. Hopefully I'm able to catch up soon. - -- Best Regards, Marek Marczykowski-Górecki Invi

Re: [qubes-devel] [GSoC] Template Manager: Interactions w/ Repos

2020-07-03 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Jul 03, 2020 at 06:16:44PM +, WillyPillow wrote: > On Friday, July 3, 2020 5:28 AM, Marek Marczykowski-Górecki > wrote: > > Besides comments I've left there, overall looks good. > > I'm not sure if splitting epoch, v

Re: [qubes-devel] [GSoC] Template Manager: Interactions w/ Repos

2020-07-02 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Jul 02, 2020 at 06:57:37PM +, WillyPillow wrote: > On Wednesday, July 1, 2020 11:10 AM, Marek Marczykowski-Górecki > wrote: > > > On Tue, Jun 30, 2020 at 07:21:23PM +, WillyPillow wrote: > > >

Re: [qubes-devel] [GSoc] Template Manager PoC

2020-06-30 Thread Marek Marczykowski-Górecki
github interface then. > For the next step, should I start implementing the interactions with the > repos? Yes :) While you are writing/testing those things, please also keep notes about testing scenarios. Can be sketch quality (list of commands to test or such). This will be useful later when int

Re: [qubes-devel] [GSoc] Template Manager PoC

2020-06-27 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Jun 27, 2020 at 08:05:49PM +, WillyPillow wrote: > On Friday, June 26, 2020 7:53 AM, Marek Marczykowski-Górecki > wrote: > > > On Thu, Jun 25, 2020 at 05:22:12PM +, WillyPillow wrote: > > > > > &g

Re: [qubes-devel] [GSoc] Template Manager PoC

2020-06-25 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Jun 25, 2020 at 05:22:12PM +, WillyPillow wrote: > On Monday, June 22, 2020 12:11 PM, Marek Marczykowski-Górecki > wrote: > > If we rely on the side effect of qubes.SyncAppmenus to not only extract > > available deskt

Re: [qubes-devel] "Qubes Architecture Next Steps: The New Qrexec Policy System" by Marek Marczykowski-Górecki & Marta Marczykowska-Górecka

2020-06-23 Thread Marek Marczykowski-Górecki
deed the example is a bit unfortunate, as it may be dangerous when used directly. I'll update it with a different target than dom0. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-po

Re: [qubes-devel] [GSoc] Template Manager PoC

2020-06-21 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Jun 20, 2020 at 04:47:49PM +, WillyPillow wrote: > On Wednesday, June 17, 2020 11:55 PM, Marek Marczykowski-Górecki > wrote: > > I'm not yet sure about interactions with qubes.SyncAppmenus call (used > > to extract

Re: [qubes-devel] Qubes 4.1 - pci passthrough problems for sys-net

2020-06-21 Thread Marek Marczykowski-Górecki
gt; > I think we need to find the right balance here, for the indicator to be > > not too-annoying. But I still think it should be clearly visible all the > > time, not only during the switch action. > > If really needed, maybe a little script could run on startup, perform a >

Re: [qubes-devel] Pool interface questions

2020-06-20 Thread Marek Marczykowski-Górecki
t. The actual data doesn't need to be available at this point. See here for documentation about various methods: https://dev.qubes-os.org/projects/core-admin/en/latest/qubes-storage.html#storage-pool-driver-api > So I guess I'd also have to proxy the Volume class for that feature? -_- I think

Re: [qubes-devel] Software Rowhammer mitigations

2020-06-19 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Jun 19, 2020 at 04:20:40PM -0700, Jean-Philippe Ouellet wrote: > On Thu, Jun 18, 2020 at 9:14 PM Marek Marczykowski-Górecki > wrote: > > > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > >

Re: [qubes-devel] Software Rowhammer mitigations

2020-06-18 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Jun 18, 2020 at 11:40:07PM -0400, Demi M. Obenour wrote: > On 2020-06-18 22:38, Marek Marczykowski-Górecki wrote: > > On Thu, Jun 18, 2020 at 09:49:14PM -0400, Demi M. Obenour wrote: > >> Would it be possible to

Re: [qubes-devel] Software Rowhammer mitigations

2020-06-18 Thread Marek Marczykowski-Górecki
lready - yet, I see many research papers with similar ideas, some from many years ago, and exactly zero real-life working implementations. Anyway, this is rather a question to relevant hypervisor developers (Xen in this case). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: B

Re: [qubes-devel] Qubes 4.1 - pci passthrough problems for sys-net

2020-06-17 Thread Marek Marczykowski-Górecki
IOMMU (at least until PV is > > completely removed), please provide patches implementing the second > > point above. Then, I'll add the first one. > > A boot parameter would be a good choice I think. Nobody would add a boot > parameter and switch vms to pv mode "by accident

Re: [qubes-devel] Qubes 4.1 - pci passthrough problems for sys-net

2020-06-15 Thread Marek Marczykowski-Górecki
't tried it, but it should be possible. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQ

Re: [qubes-devel] [GSoc] Template Manager Draft Design & Questions

2020-06-14 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Jun 09, 2020 at 12:35:48PM +, WillyPillow wrote: > On Sunday, June 7, 2020 11:39 PM, Marek Marczykowski-Górecki > wrote: > > [1] > > https://dev.qubes-os.org/projects/core-admin/en/latest/qubes-features.html#qv

[qubes-devel] Re: [qubes-project] Re: Help create a Qubes Users Forum!

2020-06-13 Thread Marek Marczykowski-Górecki
e for notifications about every single message, but I guess it will be hard to load back into discourse if we'd ever need to. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad

Re: [qubes-devel] [GSoc] Template Manager Draft Design & Questions

2020-06-07 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Jun 07, 2020 at 01:39:59PM +, WillyPillow wrote: > On Friday, June 5, 2020 4:53 AM, Marek Marczykowski-Górecki > wrote: > > > On Wed, Jun 03, 2020 at 07:02:01PM +, WillyPillow wrote: > > > There may be u

Re: [qubes-devel] [GSoc] Template Manager Draft Design & Questions

2020-06-04 Thread Marek Marczykowski-Górecki
> > "There are two hard things in computer science: cache invalidation, naming > > things, and off-by-one errors." > > Jokes aside, I think `qtm`, as proposed in #1326, is a reasonable name for the > CLI tool. What about qvm-template? > - - - > > By the

[qubes-devel] organising github-issues

2020-06-03 Thread Marek Marczykowski-Górecki
long list). But I'm not sure if it helps with anything I mentioned in this email. [1] https://github.com/QubesOS/qubes-issues/issues/5863 [2] https://github.com/QubesOS/qubes-issues/issues/5875 [3] https://github.com/QubesOS/qubes-issues/issues/5791 - -- Best Regards, Marek Marczykowski-Górecki Inv

Re: [qubes-devel] Re: Qubes 4.1 upgraded to Fedora 32 in dom0

2020-06-02 Thread Marek Marczykowski-Górecki
ts > python2-chardet > python2-crypto > python2-qubesadmin > python2-singledispatch > python2-backgports_abc > > All are listed under 'removing dependent packages' when running > qubes-dom0-update, yet all are left in place. - -- Best Regards, Marek Marczyk

Re: [qubes-devel] Re: Qubes 4.1 upgraded to Fedora 32 in dom0

2020-05-31 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, May 27, 2020 at 11:21:57PM -0700, Foppe de Haan wrote: > > > On Wednesday, May 27, 2020 at 3:57:26 PM UTC+2, Marek Marczykowski-Górecki > wrote: > > > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256

Nvidia driver issue (was: Re: [qubes-devel] [GSoC] Progress, Plans, and Questions)

2020-05-27 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 [moving to a separate sub-thread] On Thu, May 28, 2020 at 03:18:08AM +, WillyPillow wrote: > On Tuesday, May 26, 2020 11:52 AM, Marek Marczykowski-Górecki > wrote: > > > On Mon, May 25, 2020 at 05:19:04PM +, Wi

[qubes-devel] Qubes 4.1 upgraded to Fedora 32 in dom0

2020-05-27 Thread Marek Marczykowski-Górecki
software is updated 3. domains widget doesn't work (it crashes on startup, flashing)[3] [1] https://github.com/QubesOS/qubes-issues/issues/5763 [2] https://github.com/QubesOS/qubes-issues/issues/4370 [3] https://github.com/QubesOS/qubes-issues/issues/5854 - -- Best Regards, Marek Marczykowski-Górecki

Re: [qubes-devel] Re: [qubes-project] RFC Offline Documentation

2020-05-26 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, May 26, 2020 at 12:50:39PM -0700, Sarvottam Kumar wrote: > > > On Tuesday, May 26, 2020 at 8:24:39 AM UTC+5:30, Marek Marczykowski-Górecki > wrote: > > A technical detail: I would be careful about requirin

Re: [qubes-devel] [GSoC] Progress, Plans, and Questions

2020-05-25 Thread Marek Marczykowski-Górecki
that instead. Yes, configuring things within a VM is rather a task for salt. But you can totally create VMs and set their properties via Admin API. In fact, all qvm-* tools use Admin API to do their things. It's just not that visible when running in dom0, because policy is bypassed in this c

Re: [qubes-devel] IPv6 setup for OpenBSD HVM

2020-05-25 Thread Marek Marczykowski-Górecki
ilding a custom kernel. > I would prefer to avoid that. That's a bummer. Are there any plans for userspace access to those interfaces? Without them, you won't have qrexec neither (if you'd like this to be some next step). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Bec

[qubes-devel] Re: [qubes-project] RFC Offline Documentation

2020-05-25 Thread Marek Marczykowski-Górecki
pVM so that users can open it whenever they want. > Here I'm looking for suggestions so feel free to share your opinion. Oh, you've covered this point already :) I would first try to search for existing applications like that. There is for example Yelp[2], but maybe there is something more lightweight

Re: [qubes-devel] Safe Arch install

2020-05-24 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, May 24, 2020 at 04:12:27PM -0400, Demi M. Obenour wrote: > On 2020-05-24 15:58, Marek Marczykowski-Górecki wrote:>> That makes sense. > Writing to a qube’s root volume from dom0 is a > >> safe operation, since i

Re: [qubes-devel] Safe Arch install

2020-05-24 Thread Marek Marczykowski-Górecki
gs-file (the "tplspec" parts) with the build process. > > this is mostly needed for the mirage templates. > > That makes sense. Writing to a qube’s root volume from dom0 is a > safe operation, since it doesn’t do anything that the qube could > not already do itself.

[qubes-devel] new issue template "support / question"

2020-05-23 Thread Marek Marczykowski-Górecki
bes-os.org/support/ ? - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl7JG64ACg

[qubes-devel] QubesOS and 3mdeb "minisummit" 2020 - starting online today!

2020-05-20 Thread Marek Marczykowski-Górecki
ive stream are here: https://twitter.com/3mdeb_com/status/1263068441319223296 - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP

Re: [qubes-devel] What is the best way to install custom unofficial templates on QubesOS?

2020-05-14 Thread Marek Marczykowski-Górecki
ontent of this one is discarded at each VM shutdown More details here: https://www.qubes-os.org/doc/template-implementation/ - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad

Re: [qubes-devel] GSoD 2020 Introduction

2020-05-14 Thread Marek Marczykowski-Górecki
untu, GNOME, and Internet Archive. > Besides writing, I've also worked as a web developer in my two previous > internships. Thanks for the above description and the link, there is quite impressive collection :) - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it

Re: [qubes-devel] GSoD 2020

2020-05-13 Thread Marek Marczykowski-Górecki
description itself project please include also a plan how you want to approach it. Things like proposed structure, steps to achieve it etc. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is to

Re: [qubes-devel] Thunderbolt port attack

2020-05-12 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, May 12, 2020 at 05:36:07PM -0700, Brendan Hoar wrote: > On Tuesday, May 12, 2020 at 8:01:50 PM UTC-4, Marek Marczykowski-Górecki > wrote: > > > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > >

Re: [qubes-devel] Thunderbolt port attack

2020-05-12 Thread Marek Marczykowski-Górecki
notice. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl67OOYACgkQ24/THMrX 1yy

Re: [qubes-devel] Fedora 30 approaching EOL, Fedora 31 TemplateVM available, Fedora 32 TemplateVM in testing

2020-04-30 Thread Marek Marczykowski-Górecki
s a > broken template. AFAIR dnf system-upgrade doesn't fully work on Qubes, because it performs the update before qrexec is started, which means you'll most likely hit 60s startup timeout. Take a look at upgrade documentation here: https://www.qubes-os.org/doc/template/fedora/upgrade/ -

Re: [qubes-devel] Qubes Canary #23

2020-04-15 Thread Marek Marczykowski-Górecki
il signature verifies correctly. On the other hand, I get bad signature on yours email, probably because of automatically added footer (use gpg inline instead of mime to avoid the issue - this way the footer will be outside of the signed part). - -- Best Regards, Marek Marczykowski-Górecki Invi

Re: [qubes-devel] Qubes network server: 4.0 and beyond

2020-04-13 Thread Marek Marczykowski-Górecki
happy to work with > anyone on this issue. > > Thanks in advance! > - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SI

Printers (was: Re: [qubes-devel] Re: Refactoring PDF Converter (and other scripts))

2020-04-02 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Apr 02, 2020 at 09:59:32PM -0400, Demi M. Obenour wrote: > On 2020-04-02 21:46, Marek Marczykowski-Górecki wrote:>> Marek: is OCR on a > converted PDF safe? Being able to reconstruct the > >> Also, could this be

<    1   2   3   4   5   6   7   8   >