Page MenuHomePhabricator
Feed Advanced Search

May 17 2020

Patrick closed T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on as Resolved.

Awesome!

May 17 2020, 9:21 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Yes, worth it. I guess lots of people are going to try Whonix-Host inside a virtual machine before considering installation on real hardware. That's why I even would like to have ability to run Whonix-Host inside VirtualBox.

Please post new tickets in forums as per:
https://forums.whonix.org/t/abolishing-whonix-phabricator-issue-tracker-moving-issue-tracking-to-forums-migrating-phabricator-whonix-org-to-forums-whonix-org/7112

May 17 2020, 8:54 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

May 16 2020

Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

But forgot to add sudo install_package_list+=" debug-misc "...

May 16 2020, 5:05 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

May 15 2020

onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Just built 15.0.1.3.6-developers-only

May 15 2020, 11:42 AM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Great! Will try to build tomorrow and report back... asap :)

May 15 2020, 1:11 AM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Please add your build commands to Whonix wiki Dev/Whonix-Host, then I can add suggestion there how to improve these.

Not sure what you mean here?

May 15 2020, 1:05 AM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

That's probably because of T950. You'd need to remove both:

quiet loglevel=0

I see. But I won't lose time trying to debug this particular build, I will just try a new one and see if the problem persists. Had some problems with lack of space on the VM I am building with, maybe related. Not worth debugging if it's a one time thing. We'll see.

May 15 2020, 12:05 AM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

May 14 2020

Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Seems I have quite a flexible notion of "asap" :)...

May 14 2020, 9:11 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Seems I have quite a flexible notion of "asap" :)...

May 14 2020, 4:47 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

Apr 23 2020

Patrick closed T928: install xfce4-power-manager on Whonix Host and Kicksecure Host as Resolved.

xfce4-power-manager is installed on Whonix-Host in 15.0.1.3.2-developers-only.

Apr 23 2020, 9:37 PM · Whonix 15, whonix-libvirt, live-mode, Whonix, Whonix-Host
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Great news! I am rebuilding the whole package Host+gw+ws now, excited to test it out! Will report asap.

Apr 23 2020, 4:18 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick reassigned T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on from Patrick to onion_knight2.
echo "options overlay metacopy=on" > /etc/modprobe.d/overlay.conf 
update-initramfs -u
Apr 23 2020, 1:01 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

Apr 21 2020

onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

That would be OK but this is not my preferred solution. Reason: an unclean shutdown in Whonix installed persistent mode would with a subsequent boot into live mode would result in a failed reboot into Whonix installed live mode.

Apr 21 2020, 8:34 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Awesome analysis and description!

Apr 21 2020, 6:28 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Some progress made as of Whonix-Host 15.0.1.2.7:

Apr 21 2020, 3:15 AM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

Mar 30 2020

Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

[1] There is currently no trigger (systemd unit file) to execute /usr/lib/whonix-libvirt/persistent-mode-to-read-write.

Mar 30 2020, 5:27 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

Mar 26 2020

onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

As of 15.0.1.0.7, the following behavior is observed:

Mar 26 2020, 10:25 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

Mar 21 2020

Patrick added a project to T928: install xfce4-power-manager on Whonix Host and Kicksecure Host: Whonix 15.
Mar 21 2020, 11:39 AM · Whonix 15, whonix-libvirt, live-mode, Whonix, Whonix-Host

Mar 17 2020

onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Do you know how to run calamares hook scripts? I think I saw this before but I can't find it anymore. Or we have to invent our own mini calamares module similar to how package calamares-settings-debian invented new calamares modules?

Mar 17 2020, 2:25 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

I don't know. Not implemented yet. Currently installed (persistent) Whonix-Host does not have live-boot option.

Mar 17 2020, 1:19 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick added a project to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on: Whonix 15.
Mar 17 2020, 1:14 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

Mar 16 2020

onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

I think that is only here:
https://github.com/Whonix/Whonix/blob/master/build-steps.d/1800_copy_vms_into_raw#L35

Mar 16 2020, 4:47 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

I agree that a solution would probably to run some kind of script at the end of the Calamares installtion to revert ro to rw.

Mar 16 2020, 8:22 AM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

There are two read-only parameters:

Mar 16 2020, 12:20 AM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

Mar 15 2020

onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

I guess images will be set to kvm images read-only when booted in live iso mode (and probably live mode too). But once installed, images are still set to live mode. That would be probably kvm images read-only is set when run in iso live mode, cached in RAM and then installed to local disk?

Mar 15 2020, 9:45 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Good catch! Merged.

Mar 15 2020, 9:13 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Fixed by adding

Mar 15 2020, 5:22 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

I added whoami in the script and it confirmed it runs as root.

Mar 15 2020, 4:44 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Yes, it should be run by root. Maybe it is run by root but somehow the changes don't take place as they should. More debugging could help.

Mar 15 2020, 3:09 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Pretty sure it is run by root.

Mar 15 2020, 2:37 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

It seems that https://github.com/Whonix/whonix-libvirt/blob/master/usr/lib/whonix-libvirt/live-mode-to-read-only is not ran by root. Thus it cannot get the virsh list --all (returns void) nor change the VM xml configuration file.

Mar 15 2020, 1:51 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

Mar 12 2020

Patrick changed the status of T928: install xfce4-power-manager on Whonix Host and Kicksecure Host from Open to testing-in-next-build-required.

https://github.com/Whonix/anon-meta-packages/commit/9550d47959e37cb8cca508e169c121dc65cde342

Mar 12 2020, 9:34 AM · Whonix 15, whonix-libvirt, live-mode, Whonix, Whonix-Host
Patrick updated the task description for T928: install xfce4-power-manager on Whonix Host and Kicksecure Host.
Mar 12 2020, 9:30 AM · Whonix 15, whonix-libvirt, live-mode, Whonix, Whonix-Host
Patrick changed the status of T919: Whonix Live Branding from Open to testing-in-next-build-required.

https://forums.whonix.org/t/whonix-host-calamares-branding-suggestion/7772/8

Mar 12 2020, 9:29 AM · Whonix, live-mode
Patrick closed T819: persistent / live mode indicator systray - graphical indication on the desktop that system is running in live mode vs persistent mode as Resolved.
Mar 12 2020, 9:29 AM · live-mode, Whonix

Mar 11 2020

Patrick triaged T968: Bullseye: live-boot needs GRUB_DISABLE_LINUX_UUID="true" parameter in /etc/grub.d/11_linux_live as Normal priority.
Mar 11 2020, 2:14 PM · Debian version 11 codename Bullseye, Whonix, live-mode

Feb 29 2020

Patrick closed T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time as Resolved.

Works well in Non-Qubes-Whonix. Solution was this one:

Feb 29 2020, 8:26 AM · whonix-base-files, live-mode, Whonix, Whonix 15

Aug 31 2019

Patrick updated the task description for T919: Whonix Live Branding.
Aug 31 2019, 3:49 PM · Whonix, live-mode
Patrick updated the task description for T919: Whonix Live Branding.
Aug 31 2019, 3:49 PM · Whonix, live-mode
Patrick updated the task description for T919: Whonix Live Branding.
Aug 31 2019, 3:47 PM · Whonix, live-mode

Aug 21 2019

Patrick changed the status of T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on from Open to testing-in-next-build-required.

Should work on manual invocation.

Aug 21 2019, 9:13 AM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

For the record, this is the diff being generated.

Aug 21 2019, 8:38 AM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

Aug 19 2019

Patrick triaged T928: install xfce4-power-manager on Whonix Host and Kicksecure Host as Normal priority.
Aug 19 2019, 4:22 PM · Whonix 15, whonix-libvirt, live-mode, Whonix, Whonix-Host
Patrick added projects to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on: whonix-libvirt, Whonix-Host.
Aug 19 2019, 3:47 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick claimed T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.
Aug 19 2019, 3:45 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

By default, the VMs do not start because the virtual disks are not set to readonly. This is only needed when using the ISO though. Might stay this way as long as the user is correctly advised to change to set the disk to readonly mode.

Aug 19 2019, 3:45 PM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix

Jul 16 2019

marmarek added a comment to T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
In T913#18744, @Patrick wrote:

Do you see any issues with "create home directory on first login" in Qubes?

Jul 16 2019, 1:07 AM · whonix-base-files, live-mode, Whonix, Whonix 15
Patrick added a comment to T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.

Can you give some more context here?

Jul 16 2019, 12:42 AM · whonix-base-files, live-mode, Whonix, Whonix 15

Jul 15 2019

marmarek added a comment to T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.

Can you give some more context here? Is it the problem that user is created too early (before /etc/skel is fully populated)? Or is it a problem that it's created at all? Should there be a difference between Qubes and non-Qubes case?

Jul 15 2019, 11:58 PM · whonix-base-files, live-mode, Whonix, Whonix 15
Patrick updated the task description for T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
Jul 15 2019, 6:23 PM · whonix-base-files, live-mode, Whonix, Whonix 15

Jul 14 2019

Patrick updated the task description for T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
Jul 14 2019, 9:29 AM · whonix-base-files, live-mode, Whonix, Whonix 15
Patrick updated subscribers of T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
Jul 14 2019, 8:42 AM · whonix-base-files, live-mode, Whonix, Whonix 15

Jun 14 2019

Patrick added a project to T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time: whonix-base-files.
Jun 14 2019, 3:00 PM · whonix-base-files, live-mode, Whonix, Whonix 15
Patrick updated the task description for T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
Jun 14 2019, 2:57 PM · whonix-base-files, live-mode, Whonix, Whonix 15
Patrick created T919: Whonix Live Branding.
Jun 14 2019, 2:54 PM · Whonix, live-mode
Patrick updated the task description for T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
Jun 14 2019, 11:51 AM · whonix-base-files, live-mode, Whonix, Whonix 15
Patrick created T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.
Jun 14 2019, 11:27 AM · Whonix 15, Whonix-Host, whonix-libvirt, live-mode, Whonix
Patrick created T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
Jun 14 2019, 11:24 AM · whonix-base-files, live-mode, Whonix, Whonix 15

Apr 6 2019

Patrick closed T886: add grub-live as Resolved.
Apr 6 2019, 12:38 AM · live-mode, Debian version 10 codename Buster, Whonix, Whonix 15

Jan 12 2019

Patrick added a project to T886: add grub-live: live-mode.
Jan 12 2019, 7:34 AM · live-mode, Debian version 10 codename Buster, Whonix, Whonix 15

Sep 17 2018

Patrick added a project to T819: persistent / live mode indicator systray - graphical indication on the desktop that system is running in live mode vs persistent mode: live-mode.
Sep 17 2018, 9:29 AM · live-mode, Whonix
Patrick created live-mode.
Sep 17 2018, 9:29 AM