QubesOS / qubes-issues

The Qubes OS Project issue tracker
https://www.qubes-os.org/doc/issue-tracking/
536 stars 48 forks source link

Document qubes.PostInstall service, `/etc/qubes/post-install.d`, qvm-features-request #2829

Closed marmarek closed 5 years ago

marmarek commented 7 years ago

Document mechanism used by VMs (especially templates) to announce what "features" it support. This apply to things like:

This is about #1637

marmarek commented 7 years ago

@adrelanos can you list what dom0 changes you'd like for better privacy in Whonix VMs (both WS and GW)?

adrelanos commented 7 years ago

@adrelanos can you list what dom0 changes you'd like for better privacy in Whonix VMs (both WS and GW)?

That's a pretty broad question.

Generally, not just dom0:

dom0 specific:


Block clflush and tsc instructions. Remove all timers. Avoid multi-threading VMs. Alternatively use non-interleaved NUMA with pinned vCPUs.


Pin vCPUs to separate pCPUs. Block tsc instructions. Remove all timers.

qubesos-bot commented 5 years ago

Automated announcement from builder-github

The package qubes-core-dom0-4.0.33-1.fc25 has been pushed to the r4.0 testing repository for dom0. To test this update, please install it with the following command:

sudo qubes-dom0-update --enablerepo=qubes-dom0-current-testing

Changes included in this update

qubesos-bot commented 5 years ago

Automated announcement from builder-github

The package qubes-core-dom0-4.0.37-1.fc25 has been pushed to the r4.0 stable repository for dom0. To install this update, please use the standard update command:

sudo qubes-dom0-update

Or update dom0 via Qubes Manager.

Changes included in this update