Re: [qubes-devel] Re: Refactoring PDF Converter (and other scripts)

2020-04-02 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Apr 02, 2020 at 09:20:40PM -0400, Demi M. Obenour wrote: > On 2020-04-02 21:12, Jason Phan wrote: > > On Apr 03, Marek Marczykowski-Górecki wrote: > >> The idea is to verify if they are non-malicious, not necessary &

Re: [qubes-devel] Re: Refactoring PDF Converter (and other scripts)

2020-04-02 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Apr 02, 2020 at 07:45:00PM -0500, Jason Phan wrote: > On Apr 03, Marek Marczykowski-Górecki wrote: > > Yes, self-explanatory names should be enough for simple functions. But > > still, > > more complex functions

Re: [qubes-devel] Re: Refactoring PDF Converter (and other scripts)

2020-04-02 Thread Marek Marczykowski-Górecki
PDF could access/modify other files you're trying to convert. IMO a better approach would be to use separate DisposableVMs, but _independently_ optimize their resource usage (for example you don't need the whole graphical stuff and most of other service just to convert PDF -> RGB). - -- Best Reg

Re: [qubes-devel] Re: [GSoC] Qubes Live USB

2020-03-29 Thread Marek Marczykowski-Górecki
s-os repo. Travis have time limit (1h or less) and ISO build is just below that limit. > Also, for the GSoC proposal, is there anything else I need to know? Basically this: https://www.qubes-os.org/gsoc/#student-proposal-guidelines - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Be

Re: [qubes-devel] Re: [GSoC] Qubes Live USB

2020-03-25 Thread Marek Marczykowski-Górecki
ll-deps.dpkg (debian > based), but there isn't one named install-deps.pacman (archlinux based) or > something like that. Maybe you didn't include it for a reason. Ah, I see. That makes sense to add. But in fact that part is just a sanity check - if basic build tools are installed. Starting wi

Re: [qubes-devel] GSOC Introduction

2020-03-25 Thread Marek Marczykowski-Górecki
h the USBIP + qemu (second option), as it would be mostly shell+python scripts, instead of Windows kernel drivers. If you're still interested, the next step would be writing your application with description of the project, above I have pointed you where to look for inspiration. - -- Best Regards,

Re: [qubes-devel] GSoC Introduction

2020-03-25 Thread Marek Marczykowski-Górecki
f them on just installed system. This should give you ideas for the gsoc application. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing?

Re: [qubes-devel] GSoC Introduction

2020-03-25 Thread Marek Marczykowski-Górecki
/QubesOS/qubes-issues/issues/1806 - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl58Ef4

Re: [qubes-devel] Refactoring PDF Converter (and other scripts)

2020-03-21 Thread Marek Marczykowski-Górecki
t; 2. Is there a minimum required shell version? Basically whatever is present in (oldest) supported distribution: https://www.qubes-os.org/doc/supported-versions/ This means bash 4.3 (Debian jessie). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up

Re: [qubes-devel] Re: [GSoC] Qubes Live USB

2020-03-20 Thread Marek Marczykowski-Górecki
the deb or rpm based > distributions. What do you say? This all already exists, take a look here: https://www.qubes-os.org/doc/templates/ - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read te

Re: [qubes-devel] NVIDIA RTX 20XX

2020-03-18 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Mar 14, 2020 at 10:52:09AM +0100, Marek Marczykowski-Górecki wrote: > On Sat, Mar 14, 2020 at 02:15:15AM -0700, Me wrote: > > Kernel 5.6 latest(2) > > > > dom0: sudo lspci -vv > > 45:00.0 Network controller: In

Re: [qubes-devel] Qubes-Whonix Security Enhancements - GSoC

2020-03-15 Thread Marek Marczykowski-Górecki
e. In any case I'll draft a proposal and > try to have some prototype set by the end of the week (tough schedule). > > Regards, > Harry > > PS: Frédéric, the install script for i3 is how I manage my in-VM > configuration. Split-GNU Stow too good to be true? > - -- B

Re: [qubes-devel] NVIDIA RTX 20XX

2020-03-14 Thread Marek Marczykowski-Górecki
+ is set. I'll try to find where it got desynchronized. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK2

Re: [qubes-devel] NVIDIA RTX 20XX

2020-03-13 Thread Marek Marczykowski-Górecki
ernel modules: iwlwifi > > and guest-sys-net-dm.log is attached > so again, with > 0014-xen-pciback-add-attribute-to-allow-MSI-enable-flag-w.patch works fine. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normal

Re: [qubes-devel] NVIDIA RTX 20XX

2020-03-13 Thread Marek Marczykowski-Górecki
ically: in dom0: sudo lspci -v (you can limit to the wifi card only) in sys-net: sudo lspci -v in dom0: /var/log/xen/console/guest-sys-net-dm.log - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-p

Re: [qubes-devel] NVIDIA RTX 20XX

2020-03-13 Thread Marek Marczykowski-Górecki
ild a kernel with that upstream commit reverted and original patch applied? - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN P

Re: [qubes-devel] Intel AC 9260 wifi doesn't load in vm(sys-net under qubes os) after kernel update(5.6.rc3 to 5.6.rc5)

2020-03-12 Thread Marek Marczykowski-Górecki
still have the > issue. What happens if you switch it back to 5.5 or older? - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- i

Re: [qubes-devel] GSoC Introduction

2020-03-11 Thread Marek Marczykowski-Górecki
https://github.com/QubesOS/qubes-issues/issues/2233 (linked also from GSoC ideas page). It's quite long discussion, but will give you the picture what tasks you'll face here. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally

Re: [qubes-devel] GSoC introduction

2020-03-11 Thread Marek Marczykowski-Górecki
soc/ Each entry have "Knowledge prerequisite" listed, so I'm sure you'll find something for you. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad

Re: [qubes-devel] Fedora base

2020-03-03 Thread Marek Marczykowski-Górecki
e mailing list archive first. For your convenience, here is some of the threads: https://groups.google.com/d/topic/qubes-devel/oAtGfUQa2OE/discussion - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is to

Re: [qubes-devel] Google Summer of Code Introduction.

2020-02-26 Thread Marek Marczykowski-Górecki
and install it - just to go through the change workflow. > Also do you think it would be better to use the Wayland protocol > directly or through a library (e.x. wlroots)? I'd go with a library, there is little sense to reinvent the wheel. - -- Best Regards, Marek Marczykowski-Górecki Invisibl

Re: [qubes-devel] what's the correct way to auto-start a script in dom0, whitout login.

2020-02-19 Thread Marek Marczykowski-Górecki
to modify the configuration (including startup scripts to start the VPN) and another that is actual sys-net to run this configuration, but can't really modify it persistently. And with this approach, you can use standard scripts, like described here: https://www.qubes-os.org/doc/vpn/ - -- Best Re

Re: [qubes-devel] Has Xen’s security posture improved over the years?

2020-02-11 Thread Marek Marczykowski-Górecki
rue if we consider Linux VMs only. And this would be actually preferable solution if we'd go that way. But if you want to run also other OSes (Windows?), then in practice you need qemu. And using significantly more complex/vulnerable device model for less trusted VMs doesn't sound very appealing.

Re: [qubes-devel] Re: GVT-g Discussion

2020-02-11 Thread Marek Marczykowski-Górecki
hat components are involved in GPU commands processing and how are they isolated? 3. Is it possible to enable it only for some VMs - in a way outside of VM control? - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read

Re: [qubes-devel] Intel microcode update

2020-02-05 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, Feb 05, 2020 at 10:57:19PM -0500, Demi M. Obenour wrote: > On 2020-02-04 22:26, Marek Marczykowski-Górecki wrote: > > On Tue, Feb 04, 2020 at 09:46:10PM -0500, Demi M. Obenour wrote: > >> What is the status of the Inte

Re: [qubes-devel] Intel microcode update

2020-02-04 Thread Marek Marczykowski-Górecki
Intel advisory[1], and also there is no new content in microcode repository[2]. [1] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00329.html [2] https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files - -- Best Regards, Marek Marczykowski-Górecki Invisible Thin

[qubes-devel] Re: [offlist] Re: Qubes as a GSoC voucher for Whonix

2020-01-31 Thread Marek Marczykowski-Górecki
rticipation. So, in fact much of the web interface interaction is for mentors, not org admins... As for the other question: yes, we're happy to vouch for Whonix. I think our contact registered when we were accepted was Michael. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Becau

Re: [qubes-devel] Python Target Version in dom0 for New Pull Requests

2020-01-30 Thread Marek Marczykowski-Górecki
-- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl4yvWIACgkQ24/THMrX 1yzzBAf/Yn7CIr140P9OJcM4/6

Re: [qubes-devel] 5.5 fails to boot

2020-01-27 Thread Marek Marczykowski-Górecki
-- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl4u9swACgkQ24/THMrX 1yyC3Af+MlaVkAvpcgbSKxCZfGL1m8UZ

Re: [qubes-devel] 5.5 fails to boot

2020-01-27 Thread Marek Marczykowski-Górecki
in July, Linux 5.2). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl4u2ysACg

Re: [qubes-devel] Re: Intel i7-1065G7 (10 Generation Support) - APIC Patches

2020-01-25 Thread Marek Marczykowski-Górecki
i just want to generate some activity around > this so maybe someone would come up with a answer/solution. You can try booting development builds of Qubes 4.1, which include much newer Xen version (4.13). Here is the latest one: https://openqa.qubes-os.org/tests/5493/asset/iso/Qubes-4.1-20200113-x86

Re: [qubes-devel] Qubes-Backup Troubleshooting & CLI

2020-01-25 Thread Marek Marczykowski-Górecki
/backup.py > That underlying code uses the python logger, but I'm missing where it sets up > the logger to go anywhere. It goes to journalctl. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is t

Re: [qubes-devel] Kernel-latest black screen, normal works fine

2020-01-24 Thread Marek Marczykowski-Górecki
; options from Linux cmdline. If that still doesn't tell what's wrong, then add "vga=,keep guest_loglvl=all" to Xen options and "earlyprintk=xen console=hvc0 console=tty0" to Linux options and be _very_ patient (the system startup will be very slow, but you should see kernel messa

Re: [qubes-devel] AEM upgrade locks up

2020-01-15 Thread Marek Marczykowski-Górecki
Do you have a process list? There is a initramfs regeneration in a post-install script and it can take few minutes (but definitely not half an hour). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is

Re: [qubes-devel] Encrypted /boot using GRUB LUKS module (workaround for anti-evil maid tpm 1.2 limitation)

2020-01-15 Thread Marek Marczykowski-Górecki
other guide. For example: https://cryptsetup-team.pages.debian.net/cryptsetup/encrypted-boot.html I think the main difference here is lack of update-grub tool and the need to call grub2-mkconfig -o /boot/grub2/grub.cfg. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because

[qubes-devel] Qubes 4.0.3-rc1

2020-01-14 Thread Marek Marczykowski-Górecki
. I'll let you test it for some time, but generally plan to release final 4.0.3 sometime next week. Andrew, do we want some announcement, or to avoid spamming too much, do that only about final 4.0.3? - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up

Re: [qubes-devel] Qubes 4.0.2 severe issue - dom0 kernel crash

2020-01-04 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Jan 04, 2020 at 06:37:47AM -0600, Andrew David Wong wrote: > On 2020-01-04 4:06 AM, Marek Marczykowski-Górecki wrote: > > Hi, > > > > The just released 4.0.2 has severe bug - dom0 kernel crashes on DISCARD > >

Re: [qubes-devel] Qubes 4.0.2 severe issue - dom0 kernel crash

2020-01-04 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Jan 04, 2020 at 09:28:45AM -0500, Chris Laprise wrote: > On 1/4/20 5:06 AM, Marek Marczykowski-Górecki wrote: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > > Hi, > > > > The just rele

Re: [qubes-devel] Attaching files with qvm-block: is there a security problem with this workaround?

2019-12-25 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, Dec 25, 2019 at 05:53:28PM -0500, Demi M. Obenour wrote: > On 2019-12-25 03:33, Marek Marczykowski-Górecki wrote: > > On Wed, Dec 25, 2019 at 03:00:36AM +, 'heombeeh' via qubes-devel wrote: > >> Thanks a lot for th

[qubes-devel] QSB #56: Insufficient anti-spoofing firewall rules

2019-12-25 Thread Marek Marczykowski-Górecki
org/doc/firewall/#enabling-networking-between-two-qubes [2] https://nvd.nist.gov/vuln/detail/CVE-2019-14899 - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normall

Re: [qubes-devel] Attaching files with qvm-block: is there a security problem with this workaround?

2019-12-25 Thread Marek Marczykowski-Górecki
op0/desc 'disk.img' > $ qubesdb-write /qubes-block-devices/loop0/size 536870912 > $ qubesdb-write /qubes-block-devices/loop0/mode w > > After doing this `qvm-block ls` detects the new disk, but the Qubes GUI (i.e. > the widget in the top right corner of the window manager) does n

Re: [qubes-devel] Attaching files with qvm-block: is there a security problem with this workaround?

2019-12-24 Thread Marek Marczykowski-Górecki
h it to my VM. Yes, devices excluded from udev also are excluded from qvm-block. But we have documented method to force showing them: https://www.qubes-os.org/doc/mount-lvm-image/ It works also for loop devices - simply use "loopX" instead of "dm-X" > Thanks in advance t

Re: [qubes-devel] Qubes OS on GSoC 2020

2019-12-17 Thread Marek Marczykowski-Górecki
iscuss projects here and maybe open PRs to that page. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK2

Re: [qubes-devel] Next major release of Qubes OS

2019-12-17 Thread Marek Marczykowski-Górecki
rek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl3497UACgkQ24/THMrX 1ywYnwf/TNq

Re: [qubes-devel] Next major release of Qubes OS

2019-12-13 Thread Marek Marczykowski-Górecki
/i/3jdpyf > https://imgflip.com/i/3jdq3j > > :P I like this comparison :D While the products are quite similar in goals and technology, we have sufficiently different target user base to not compete against each other in practice. And it's quite cool to share effort on this path. > Br

Re: [qubes-devel] Next major release of Qubes OS

2019-12-13 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Dec 13, 2019 at 11:16:07AM +0700, OutBackdingo wrote: > > On 12/12/19 11:52 PM, Marek Marczykowski-Górecki wrote: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > > On Thu, Dec 12, 2019 at 08:31:5

Re: [qubes-devel] Next major release of Qubes OS

2019-12-12 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Dec 12, 2019 at 08:31:55AM -0800, Foppe de Haan wrote: > > > On Friday, December 6, 2019 at 3:25:55 AM UTC+1, Marek Marczykowski-Górecki > wrote: > > > > The current plan for major features of Qubes OS 4.1 is: &g

[qubes-devel] QSB #55: Issues with PV type change and handling IOMMU on AMD (XSA-310, XSA-311)

2019-12-11 Thread Marek Marczykowski-Górecki
/advisory-310.html [2] https://xenbits.xen.org/xsa/advisory-311.html - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting

Re: [qubes-devel] Re: Compiling an ISO with kernel-latest and modifications

2019-12-11 Thread Marek Marczykowski-Górecki
0' sounds fishy here. Note the build is done within chroot environment with Fedora 25 inside, not directly on your host, so call like 'sudo dnf install pungi-legacy' won't help. What you may try is: sudo chroot chroot-dom0-fc25 dnf install pungi-legacy - -- Best Regards, Marek Marcz

Re: [qubes-devel] Next major release of Qubes OS

2019-12-10 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Dec 06, 2019 at 09:59:47PM -0500, Charles Peters wrote: > On Thu, Dec 5, 2019 at 9:25 PM Marek Marczykowski-Górecki < > marma...@invisiblethingslab.com> wrote: > > The current plan for major features of Qubes OS 4.1 is: &

Re: [qubes-devel] Next major release of Qubes OS

2019-12-07 Thread Marek Marczykowski-Górecki
plate seem to "survive" the schema validations, and therefore > the file could be available for qemu to pass to the VM. However, so far > I couldn't get it passed yet, some patching is still needed to be done.. Yes, this is one of the problems to be solved. In many cases what

Re: [qubes-devel] Next major release of Qubes OS

2019-12-06 Thread Marek Marczykowski-Górecki
int in _data/team.yml - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMr

Re: [qubes-devel] Next major release of Qubes OS

2019-12-05 Thread Marek Marczykowski-Górecki
ious paths here to be explored, with different hardware requirements, and different security properties. But that's for late 2020 at the earliest. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is

Re: [qubes-devel] More than 32 vCPU

2019-11-15 Thread Marek Marczykowski-Górecki
- -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl3PQIQACgkQ24/THMrX 1y

Re: [qubes-devel] Problem building template

2019-11-15 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Nov 15, 2019 at 01:01:00PM +, Davíð Steinn Geirsson wrote: > On Fri, Nov 15, 2019 at 04:00:41AM +0100, Marek Marczykowski-Górecki wrote: > > On Thu, Nov 14, 2019 at 10:10:56PM +, Davíð Steinn Geirsson wrote: > > > I

Re: [qubes-devel] Problem building template

2019-11-14 Thread Marek Marczykowski-Górecki
ht be to put the builder into a subdirectory rather than > directly in the root of the image. But I guess this must have worked > as-is at some point? Yes, it does work as-is. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in

Re: [qubes-devel] libusb and QubesOS USB pass through don’t work together

2019-11-09 Thread Marek Marczykowski-Górecki
ol to something simpler would work in a principle, but has two major usability issues: - DisposableVM (or more specifically: Linux VM) takes some precious memory - USBIP is slow - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which

Re: [qubes-devel] GuiVM window title prefix

2019-11-06 Thread Marek Marczykowski-Górecki
on't like lying in there. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl3DhjsACgkQ24/THM

Re: [qubes-devel] GuiVM window title prefix

2019-11-06 Thread Marek Marczykowski-Górecki
which is another reason why it needs to be easy to distinguish from yet another VM window. I'm not sure if actual VM name is that important in this tag. After all, you have just one of them visible at a given time. But it might be useful to reduce confusion (why it's calle

[qubes-devel] QSB #52: Xen issues affecting PCI passthrough and PV domains (XSA-299, XSA-302)

2019-10-31 Thread Marek Marczykowski-Górecki
y-299.html [2] https://xenbits.xen.org/xsa/advisory-302.html - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: W

[qubes-devel] Dropping Debian jessie (oldoldstable) support in R4.0

2019-10-23 Thread Marek Marczykowski-Górecki
would like to keep support for jessie in R4.0, we'll need a volunteer to test updates and fix potential issues (including build issues). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting

Re: [qubes-devel] Re: Password encryption for individual vm's

2019-10-22 Thread Marek Marczykowski-Górecki
ses: - preventing access to selected (powered off) qubes even if someone obtains access to dom0 (either by accessing running system, or obtaining disk passphrase) - more reliable removing qubes - make sure the removed data cannot be recovered from the disk with forensics tools (and k

Re: [qubes-devel] Changelogs

2019-10-22 Thread Marek Marczykowski-Górecki
for security fixes. You can find them on all the communication channels (mailing lists, website news, social media). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thi

Re: [qubes-devel] feature request: automatic managing of cpu and memory allocation

2019-10-08 Thread Marek Marczykowski-Górecki
o do anything else. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl2cgKgACgkQ24/THMrX 1y

Re: [qubes-devel] qubes-builder setup script

2019-09-13 Thread Marek Marczykowski-Górecki
email verification to upload the whole key (gpg2 doesn't like keys without any UID). So, I see two options: - switch to keys.openpgp.org and ask everyone mentioned in qubes-builder (Patrick in practice) to upload keys there - distribute keys as files Patrick, any opinion? - -- Best Regards,

[qubes-devel] QSB #51: Insufficient validation of backup compression filter on restore

2019-09-10 Thread Marek Marczykowski-Górecki
qubes-os.org/doc/backup-restore/ [4] https://www.qubes-os.org/doc/backup-emergency-restore-v4/ [5] https://www.qubes-os.org/doc/backup-emergency-restore-v3/ [6] https://www.qubes-os.org/doc/backup-emergency-restore-v2/ - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` - -- Best

Re: [qubes-devel] Re: Reminder: Please help test new updates and provide feedback!

2019-09-03 Thread Marek Marczykowski-Górecki
affecting even only testing packages get proper attention (QSB etc). And thanks to Qubes architecture, are not more common than in stable release. [1] https://github.com/QubesOS/qubes-issues/issues/5199 - -- Best Regards, Marek Marczykowski-Górecki Invisible Things L

Re: [qubes-devel] Is qemu in dom0 still a no-go?

2019-08-27 Thread Marek Marczykowski-Górecki
ivity? No, we don't want qemu (or any other device emulator) running directly in dom0. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEz

Re: [qubes-devel] HVM VM creation using UEFI ISO problems

2019-08-25 Thread Marek Marczykowski-Górecki
1 (replace VMNAME with actual VM name) To disable it: qvm-features -D VMNAME uefi - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdF

Re: [qubes-devel] qvm-create-windows-qube Automatically creates

2019-08-20 Thread Marek Marczykowski-Górecki
ook into it. I haven't looked into details nor tried it yet, but on the first sight looks really cool! - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad t

Re: [qubes-devel] Secure inter-domain communications: Argo vs historical methods

2019-08-10 Thread Marek Marczykowski-Górecki
02019.pdf - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl1PQ+QACgkQ24/THMr

Re: [Whonix-devel] [qubes-devel] Whonix 15.0.0.3.6 - Development Discussion and Testers Wanted! introduction of sdwdate-gui; Tor Browser first startup popup, disabled whonixcheck “Connecting to Tor…”

2019-08-09 Thread Marek Marczykowski-Górecki
gt; sdwdate-gui-qubes) limited availability nowadays, I don't think we can > witch to a network based client/server architecture. Ok, fair enough. > > 2a. This could break if you put something between Whonix Workstation and > > Whonix Gateway (for example VPN). But in that case automat

Re: [qubes-devel] Whonix 15.0.0.3.6 - Development Discussion and Testers Wanted! introduction of sdwdate-gui; Tor Browser first startup popup, disabled whonixcheck “Connecting to Tor…” passive popup

2019-08-09 Thread Marek Marczykowski-Górecki
ity-slider-highest.js to > /var/cache/tb-binary/.tb/tor-browser/Browser/TorBrowser/Data/Browser/profile.default/user.js. > > > cp /usr/share/torbrowser/security-slider-highest.js > /var/cache/tb-binary/.tb/tor-browser/Browser/TorBrowser/Data/Browser/profile.default/user.js > > &g

[qubes-devel] Qubes updates server issue, qubes users counter data

2019-07-03 Thread Marek Marczykowski-Górecki
the repositories should work again. But in the process, we've lost recent history of qubes users counter. If anyone have recent copy of https://tools.qubes-os.org/counter/stats.json file, please send it to me. I've found only a copy from Feb 2019. Thanks! - -- Best Regards, Marek Marczykowski

Re: [qubes-devel] Custom VM kernel from dom0

2019-07-01 Thread Marek Marczykowski-Górecki
an't wait, there is some experimental version here (to be installed in dom0): https://github.com/QubesOS/qubes-linux-pvgrub2/pull/2 Then, simply configure grub within the template and set grub2-xen-pvh as the VM kernel. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Becaus

Re: [qubes-devel] Re: Requirements for PVH stubdoms?

2019-06-30 Thread Marek Marczykowski-Górecki
; in theory it should be fine to use pcifront/pciback for that, but those won't be happy without the rest of PCI passthrough (interrupts, BAR, DMA etc) There is experimental work on qubes-devel (by Paul Durrant) on standalone PCI emulators (no qemu). While not directly solving stubdomain isssue, it m

Re: [qubes-devel] Custom VM kernel from dom0

2019-06-28 Thread Marek Marczykowski-Górecki
l-vm-support package. And here: https://github.com/QubesOS/qubes-linux-utils/tree/release4.0/kernel-modules Not sure about LFS, but here you can see how it works on Debian: https://www.qubes-os.org/doc/managing-vm-kernel/#installing-kernel-in-debian-vm > That said, tmem seems to be absent fro

Re: [qubes-devel] Backport newer 'thin-provisioning-tools' to dom0?

2019-06-28 Thread Marek Marczykowski-Górecki
cript to easily pull and rebuild packages from fc28. That would be device-mapper-persistent-data 0.7.5. Would that work for you? - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-post

Re: [qubes-devel] qemu-stubdom<=>dom0 interface changes

2019-06-25 Thread Marek Marczykowski-Górecki
oject.org/archives/html/xen-devel/2018-11/msg00067.html - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK2

Re: [qubes-devel] Python 3.6 in dom0

2019-06-21 Thread Marek Marczykowski-Górecki
gs & assets" tab). - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl0NIJkACgkQ24/THMrX 1yx7

Re: [qubes-devel] Installing qubes tools to BLFS - qrexec doesn't work

2019-06-19 Thread Marek Marczykowski-Górecki
IN && untrusted_hdr.type < MSG_MAX > Gtk-Message: GtkDialog mapped without a transient parent. This is discouraged. > got unknown msg type 147 Oh, I think you compiled gui-agent from master branch (R4.1), but run it with with R4.0 dom0. Use release4.0 branch of gui-agent (and gui-common)

Re: [qubes-devel] Installing qubes tools to BLFS - qrexec doesn't work

2019-06-18 Thread Marek Marczykowski-Górecki
> 647 root 20 00.0m 0.0m 0.0 0.0 0:00.00 Z `- > [qubes-gui-runus] Looks like a problem with starting X server. Check ~/.xsession-errors and ~/.local/share/xorg/Xorg.0.log (or other xorg log location). - -- Best Regards,

[qubes-devel] Re: Pull request for domain widget

2019-06-15 Thread Marek Marczykowski-Górecki
   don't show submenu for header; rename memory header >   whitespace fixes, better description >   remove unused code >   revert arbitrary version string > > qui/decorators.py   | 39 ++- > qui/tray/domains.py | 49 ++---

[qubes-devel] kernel package improvements - out of tree modules

2019-06-06 Thread Marek Marczykowski-Górecki
, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAlz5bVAACgkQ24/THMrX 1ywLqgf/QnENzE

Re: [qubes-devel] QubesOS 4.1 status

2019-06-05 Thread Marek Marczykowski-Górecki
map, but may not be fully ready in R4.1. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl

Re: [qubes-devel] QWT crossbuild project

2019-06-01 Thread Marek Marczykowski-Górecki
a lot of them, but given previous experience with mingw, one needs to be careful - some may actually be bugs in mingw header files, not necessary our code. > [1] https://github.com/tabit-pro/qwt-crossbuild > [2] https://github.com/QubesOS/qubes-issues/issues/3418 [3] https://github.com/QubesO

Re: [qubes-devel] sys-usb hardening

2019-05-18 Thread Marek Marczykowski-Górecki
gt; [5]: [6] https://github.com/QubesOS/qubes-issues/issues/2811 [7] https://github.com/QubesOS/qubes-issues/issues/3860 - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posti

[qubes-devel] QSB #49: Microarchitectural Data Sampling speculative side channel (XSA-297)

2019-05-15 Thread Marek Marczykowski-Górecki
e new Xen binaries. Credits See the original Xen Security Advisory. References === [1] https://xenbits.xen.org/xsa/advisory-297.html - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Be

Re: [qubes-devel] Qubes networking questions (sys-firewall vs mirage-firewall)

2019-05-05 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, May 05, 2019 at 05:51:28AM -0700, tal...@gmail.com wrote: > On Sunday, May 5, 2019 at 1:15:12 PM UTC+1, Marek Marczykowski-Górecki wrote: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > > On Sun,

Re: [qubes-devel] Qubes networking questions (sys-firewall vs mirage-firewall)

2019-05-05 Thread Marek Marczykowski-Górecki
m not sure how you handle it on mirage-firewall side, but it's also visible in xenstore state of that interface - it stays at state "2" in backend and "1" in frontend. [1] https://github.com/QubesOS/qubes-core-agent-linux/blob/e3db225aab74c26ff12d4a4e544cc5d60e1effd7/network/vif-

Re: [qubes-devel] Re: Intergrating NVIDIA or AMD 3D Acceleration into Qubes-GUI

2019-05-03 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, May 03, 2019 at 05:41:21AM -0700, Dylanger Daly wrote: > On Friday, May 3, 2019 at 9:46:02 AM UTC+1, Dylanger Daly wrote: > > On Friday, May 3, 2019 at 12:55:21 AM UTC+1, Marek Marczykowski-Górecki > > wrote: > > &g

Re: [qubes-devel] Re: Intergrating NVIDIA or AMD 3D Acceleration into Qubes-GUI

2019-05-02 Thread Marek Marczykowski-Górecki
2019 at 1:01:18 PM UTC+1, Dylanger Daly wrote: > > > > On Monday, April 29, 2019 at 4:39:45 AM UTC+1, Jean-Philippe Ouellet > > > > wrote: > > > > > On Sun, Apr 28, 2019 at 10:37 AM Dylanger Daly > > > > > wrote: > > > > > >

Re: [qubes-devel] Re: Intergrating NVIDIA or AMD 3D Acceleration into Qubes-GUI

2019-04-30 Thread Marek Marczykowski-Górecki
; physical system during boot before PCI access control has been > > configured). > > > > [1]: https://groups.google.com/d/msg/qubes-devel/7qDzq5c-iK4/7AiKMfdjAgAJ > > [2]: > > https://genode.org/documentation/release-notes/10.08#Gallium3D_and_Intel_s_Graphics_Execu

Re: [qubes-devel] Compile failure on Fedora 29. u2mfn missing.

2019-04-27 Thread Marek Marczykowski-Górecki
es" gets ran. You can avoid full rebuild by building selected components - specifically skipping those you've already built. "make help" will display the full list, so you can start with linux-kernel, which is the failing one: make linux-kernel artwork gui-common gui-daemon ...

Re: [qubes-devel] Re: Intergrating NVIDIA or AMD 3D Acceleration into Qubes-GUI

2019-04-27 Thread Marek Marczykowski-Górecki
i.sh > - appvm-scripts/etc/init.d/qubes-gui-agent > - appvm-scripts/usrbin/qubes-run-xorg > - appvm-scripts/usrbin/qubes-set-monitor-layout > > However I'm greeted with > > https://imgur.com/a/fGUB4oW > > Does anyone have any expirence with the Q

Re: [qubes-devel] Compile failure on Fedora 29. u2mfn missing.

2019-04-25 Thread Marek Marczykowski-Górecki
se isolated chroot environment for the build and this is where u2mfn module is missing. Check beginning of the log to see what have happened, the module should be installed as part of qubes-kernel-vm-support package. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because

Re: [qubes-devel] Qubes Builder untrusted.Expired signing key

2019-04-19 Thread Marek Marczykowski-Górecki
s-builder.git > > cd qubes-builder > > git tag -v `git describe` > > > > It says it is signed with key gpg: RSA key 063938BA42CFA724 > > > > The issue that there is. This key is expired or revoked. > > > > gpg: searching for "063938BA42CFA724" from

Re: [qubes-devel] Re: Something is stopping me from writing MSRs (0x150 / Undervolting to be exact)

2019-04-18 Thread Marek Marczykowski-Górecki
g you may also set: git config --global sendemail.smtpencryption tls git config sendemail.ccCmd "$PWD/scripts/get_maintainer.pl" # send one patch on the top git send-email --to=xen-de...@lists.xenproject.org -1 - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes u

Re: [qubes-devel] Subnet Mask is not accepted in HVM installation

2019-04-17 Thread Marek Marczykowski-Górecki
d gateway IP right? - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? -BEGIN PGP SIGNATURE- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl

Re: [qubes-devel] What happened to the tagging of unsafe files?

2019-04-17 Thread Marek Marczykowski-Górecki
actly the case. There were problems with getting nautilus/Dolphin extensions in a shape acceptable to upstream project. - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? --

<    1   2   3   4   5   6   7   8   >