Page MenuHomePhabricator

Whonix 13Project
ActivePublic

Members (2)

Recent Activity

Jan 31 2018

Patrick closed T764: Fingerprinting: push tor 0.3.2.9 to stable repo at time of TB 7.5 release as Resolved.
Jan 31 2018, 7:47 PM · Whonix 15, Whonix 14, Whonix 13, Whonix

Jan 25 2018

Patrick added a comment to T764: Fingerprinting: push tor 0.3.2.9 to stable repo at time of TB 7.5 release.

Done.

Jan 25 2018, 2:40 AM · Whonix 15, Whonix 14, Whonix 13, Whonix

Jan 24 2018

rustybird added a comment to T764: Fingerprinting: push tor 0.3.2.9 to stable repo at time of TB 7.5 release.

TB 7.5 was released today, so you may want to transition this to the stable repository.

Jan 24 2018, 12:06 AM · Whonix 15, Whonix 14, Whonix 13, Whonix

Jan 22 2018

Patrick added a comment to T764: Fingerprinting: push tor 0.3.2.9 to stable repo at time of TB 7.5 release.

(Adjusting tags as reminder.)

Jan 22 2018, 2:56 AM · Whonix 15, Whonix 14, Whonix 13, Whonix
Patrick added projects to T764: Fingerprinting: push tor 0.3.2.9 to stable repo at time of TB 7.5 release: Whonix 14, Whonix 15.
Jan 22 2018, 2:56 AM · Whonix 15, Whonix 14, Whonix 13, Whonix

Jan 21 2018

Patrick added a project to T764: Fingerprinting: push tor 0.3.2.9 to stable repo at time of TB 7.5 release: Whonix 13.
Jan 21 2018, 3:39 PM · Whonix 15, Whonix 14, Whonix 13, Whonix

Oct 31 2017

Patrick added a comment to T695: Whonix running as Qubes DispVM uses saved clock.

Qubes-Whonix DispVMs won't get any more development attention in Qubes
R3.2 because so much has changed. Please look into Qubes R4.

Oct 31 2017, 9:29 PM · Whonix 14, Whonix 13, Whonix, sclockadj
awokd added a comment to T695: Whonix running as Qubes DispVM uses saved clock.

I didn't notice this bug earlier but caught a reference in one of the Qubes mailing list discussions. For what it's worth, I got this to function under Qubes 3.2 by deleting the sdwdate systemd unit files. It has been a while but I think I did that in the whonix-ws template. The dispvm appears to call bootclockrandomization on every start so time correlation is avoided and I no longer encounter times off by 2+ weeks.

Oct 31 2017, 6:05 PM · Whonix 14, Whonix 13, Whonix, sclockadj

Oct 28 2017

Patrick closed T724: whonixcheck fixes for Qubes R4 as Resolved.

Whonix 13: uploaded to jessie-proposed-updates.

Oct 28 2017, 11:38 AM · Whonix, Whonix 14, Whonix 13, whonixcheck

Oct 25 2017

Patrick added a comment to T724: whonixcheck fixes for Qubes R4.

Whonix 14:
https://github.com/Whonix/whonixcheck/commit/967bea77f61c03f0b2d52cd446cedc6c0cca7e27

Oct 25 2017, 2:10 PM · Whonix, Whonix 14, Whonix 13, whonixcheck

Oct 24 2017

Patrick added a comment to T724: whonixcheck fixes for Qubes R4.

Whonix 14:
https://github.com/Whonix/whonixcheck/commit/ac614c35717fb3450b6415b3010396d1549ab7d7

Oct 24 2017, 11:19 PM · Whonix, Whonix 14, Whonix 13, whonixcheck
Patrick created T724: whonixcheck fixes for Qubes R4.
Oct 24 2017, 2:26 PM · Whonix, Whonix 14, Whonix 13, whonixcheck

Oct 20 2017

Patrick closed T491: port whonixcheck and tb-updater to Qubes qrexec based updates proxy as Resolved.
Oct 20 2017, 5:02 PM · Whonix 14, Whonix 13, tb-updater, Whonix, Qubes, whonixcheck
Patrick claimed T491: port whonixcheck and tb-updater to Qubes qrexec based updates proxy.
Oct 20 2017, 4:58 PM · Whonix 14, Whonix 13, tb-updater, Whonix, Qubes, whonixcheck
Patrick closed T723: Qubes R4 RC1 - Whonix 13 - updates proxy test failing sometimes as Resolved.

Uploaded to jessie-proposed-updates.

Oct 20 2017, 4:46 PM · Whonix, Whonix 13, Whonix 14
Patrick added a comment to T723: Qubes R4 RC1 - Whonix 13 - updates proxy test failing sometimes.

While I was at it, improved that popup message a bit. It's hard for me to word what to say in such a situation.

Oct 20 2017, 4:38 PM · Whonix, Whonix 13, Whonix 14
Patrick added a comment to T491: port whonixcheck and tb-updater to Qubes qrexec based updates proxy.

tb-updater fix for Whonix 14 / master.

Oct 20 2017, 4:02 PM · Whonix 14, Whonix 13, tb-updater, Whonix, Qubes, whonixcheck
Patrick added a comment to T491: port whonixcheck and tb-updater to Qubes qrexec based updates proxy.

Backported to Whonix 13 tb-updater.

Oct 20 2017, 3:56 PM · Whonix 14, Whonix 13, tb-updater, Whonix, Qubes, whonixcheck
Patrick added a comment to T491: port whonixcheck and tb-updater to Qubes qrexec based updates proxy.

Here is the fix for tb-updater. Please have a look. Untested. Will test now. If it works, I will backport to Whonix 13 tb-updater.

Oct 20 2017, 3:43 PM · Whonix 14, Whonix 13, tb-updater, Whonix, Qubes, whonixcheck
Patrick added a comment to T491: port whonixcheck and tb-updater to Qubes qrexec based updates proxy.

Is that changing to 127.0.0.1 work on Qubes 3.2?

Oct 20 2017, 3:42 PM · Whonix 14, Whonix 13, tb-updater, Whonix, Qubes, whonixcheck
marmarek added a comment to T491: port whonixcheck and tb-updater to Qubes qrexec based updates proxy.

Is that changing to 127.0.0.1 work on Qubes 3.2? Anyway, yes, it should be good enough for Qubes 4.0.

Oct 20 2017, 3:33 PM · Whonix 14, Whonix 13, tb-updater, Whonix, Qubes, whonixcheck
Patrick edited projects for T491: port whonixcheck and tb-updater to Qubes qrexec based updates proxy, added: Whonix 13, Whonix 14; removed Whonix 15.
Oct 20 2017, 3:28 PM · Whonix 14, Whonix 13, tb-updater, Whonix, Qubes, whonixcheck
marmarek added a comment to T723: Qubes R4 RC1 - Whonix 13 - updates proxy test failing sometimes.

sys-whonix is started by first request to updates proxy (if not already running). In most cases it will be that connectivity check. I think connect timeout doesn't matter here, as connection (in terms of TCP) is to localhost, instant. Only the response comes later.
I guess the problem is that the warning is displayed, while the connectivity check is still running (i.e. race condition). Since sys-whonix takes some time to start, it happens reliably. Maybe some dependencies between those services would help (is it possible to order GUI application after system service startup?). Or some lock file to synchronize those things?
If none of above is possible, some solution would be ordering connectivity check with Before=qubes-gui-agent.service. But I'd treat this as last resort.

Oct 20 2017, 3:18 PM · Whonix, Whonix 13, Whonix 14
Patrick added a comment to T723: Qubes R4 RC1 - Whonix 13 - updates proxy test failing sometimes.

A timeout might not be sufficient? Just starting the whonix-gw (or whonix-ws) template alone does not result in invoking Qubes updates proxy qrexec call and thereby starting sys-whonix? Imagine the user just starting whonix-gw (or whonix-ws) and then getting distracted, doing something else, not upgrading.

Oct 20 2017, 3:11 PM · Whonix, Whonix 13, Whonix 14
Patrick created T723: Qubes R4 RC1 - Whonix 13 - updates proxy test failing sometimes.
Oct 20 2017, 3:07 PM · Whonix, Whonix 13, Whonix 14

Oct 9 2017

Patrick closed T710: qubes-whonix build failure as Resolved.
Oct 9 2017, 9:32 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
Patrick closed T671: old Tor Browser versions in /var/cache/tb-binary/.tb/ accumulate in Qubes-Whonix, users run into full up disk error issues as Resolved.
Oct 9 2017, 9:29 AM · Whonix 13, Whonix 14, Qubes, Whonix

Oct 8 2017

Patrick added a comment to T710: qubes-whonix build failure.
> Just setting `tbb_version` or `tbb_hardcoded_version` variable isn't enough, because it isn't propagated through all the layers to postinst of tb-updater.
Oct 8 2017, 11:52 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
marmarek added a comment to T710: qubes-whonix build failure.

https://github.com/Whonix/qubes-template-whonix/pull/1

Just setting tbb_version or tbb_hardcoded_version variable isn't enough, because it isn't propagated through all the layers to postinst of tb-updater. But creating temporarily a configuration file works (in /etc/torbrowser.d).
Use tbb_version there, because tbb_hardcoded_version is unconditionally overridden by /usr/share/tb-updater/tbb_hardcoded_version. But later is ignored if tbb_version is already set.

Oct 8 2017, 10:56 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
Patrick reopened T710: qubes-whonix build failure as "Open".
Oct 8 2017, 1:13 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
Patrick added a comment to T710: qubes-whonix build failure.

marmarek (Marek Marczykowski-Górecki):

marmarek added a comment.

The problem is back again, 7.0.4 is no longer available at https://dist.torproject.org/torbrowser/
What is the easiest/elegant way to choose different version, without modifying tb-updater package? Some env variable? Some config file? I don't consider https://github.com/SimonSelg/qubes-template-whonix/blob/SimonSelg-fix-tb-updater/whonix-gateway/04_install_qubes_post.sh#L65-L79 elegant...
Oct 8 2017, 1:12 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix

Oct 7 2017

marmarek added a comment to T710: qubes-whonix build failure.

The problem is back again, 7.0.4 is no longer available at https://dist.torproject.org/torbrowser/
What is the easiest/elegant way to choose different version, without modifying tb-updater package? Some env variable? Some config file? I don't consider https://github.com/SimonSelg/qubes-template-whonix/blob/SimonSelg-fix-tb-updater/whonix-gateway/04_install_qubes_post.sh#L65-L79 elegant...

Oct 7 2017, 3:39 PM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix

Aug 30 2017

Patrick closed T710: qubes-whonix build failure as Resolved.
Aug 30 2017, 10:40 PM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix

Aug 28 2017

Patrick added a comment to T671: old Tor Browser versions in /var/cache/tb-binary/.tb/ accumulate in Qubes-Whonix, users run into full up disk error issues.

Fixed package uploaded to jessie-proposed-updates.

Aug 28 2017, 1:52 PM · Whonix 13, Whonix 14, Qubes, Whonix

Aug 26 2017

marmarek added a comment to T710: qubes-whonix build failure.

Yes, it works now: https://travis-ci.org/marmarek/qubes-template-whonix/builds/263033873

Aug 26 2017, 1:38 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix

Aug 25 2017

marmarek added a comment to T671: old Tor Browser versions in /var/cache/tb-binary/.tb/ accumulate in Qubes-Whonix, users run into full up disk error issues.

The idea was to keep X newest entries. not oldest, right? So the first order is right (the code skip X "first" directories). Also, I'd trust more file names, not modification time - the later is easy to mess up (and a consequence will be removing wrong directory - possibly containing just modified data).

Aug 25 2017, 7:46 PM · Whonix 13, Whonix 14, Qubes, Whonix

Aug 24 2017

Patrick added a comment to T710: qubes-whonix build failure.

tb-updater with updated hardcoded Tor Browser version is now available in Whonix jessie-proposed-updates repository. Could you try a build please? Quite likely it will go past that issue now.

Aug 24 2017, 5:17 PM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
Patrick added a comment to T671: old Tor Browser versions in /var/cache/tb-binary/.tb/ accumulate in Qubes-Whonix, users run into full up disk error issues.

The version with that fix is now available from jessie-proposed-updates.

Aug 24 2017, 5:15 PM · Whonix 13, Whonix 14, Qubes, Whonix
Patrick added a comment to T671: old Tor Browser versions in /var/cache/tb-binary/.tb/ accumulate in Qubes-Whonix, users run into full up disk error issues.

That works better. But still not sufficient. It's in the wrong order.

Aug 24 2017, 11:17 AM · Whonix 13, Whonix 14, Qubes, Whonix

Aug 15 2017

marmarek added a comment to T671: old Tor Browser versions in /var/cache/tb-binary/.tb/ accumulate in Qubes-Whonix, users run into full up disk error issues.

I've tried glob, but I need reversed order and failed to do that with glob. ls -dr should do. Unless $tb_browser_folder itself contains spaces...

Aug 15 2017, 8:03 PM · Whonix 13, Whonix 14, Qubes, Whonix
Patrick added a comment to T671: old Tor Browser versions in /var/cache/tb-binary/.tb/ accumulate in Qubes-Whonix, users run into full up disk error issues.

Thank you very much for the PR!

Aug 15 2017, 7:31 PM · Whonix 13, Whonix 14, Qubes, Whonix

Aug 12 2017

marmarek added a comment to T671: old Tor Browser versions in /var/cache/tb-binary/.tb/ accumulate in Qubes-Whonix, users run into full up disk error issues.

Proposed fix here: https://github.com/Whonix/tb-updater/pull/1

Aug 12 2017, 12:49 PM · Whonix 13, Whonix 14, Qubes, Whonix

Aug 10 2017

marmarek added a comment to T710: qubes-whonix build failure.

Indeed, TEMPLATE_OPTIONS variable wasn't properly propagated. Fixing this fixes whonix-gateway build:
https://travis-ci.org/marmarek/qubes-template-whonix/builds/263033866

Aug 10 2017, 1:16 PM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix

Aug 9 2017

Patrick added a comment to T710: qubes-whonix build failure.

tb-updater must not be installed on Whonix-Gateway at all cost. It's a blocker, since that messes up a carefully selected and package selection.

Aug 9 2017, 9:54 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
SimonSelg added a comment to T710: qubes-whonix build failure.
Aug 9 2017, 2:36 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
marmarek added a comment to T710: qubes-whonix build failure.

Also, it worked before (when tor browser 7.0 was still downloadable)... See builds history on travis (https://travis-ci.org/marmarek/qubes-template-whonix/builds).

Aug 9 2017, 2:28 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
marmarek added a comment to T710: qubes-whonix build failure.

In above linked travis job, workstation build (17.6) fails with:

(Debugging information: curl_status_message: [22] - [HTTP page not retrieved. The requested url was not found or returned another error with the HTTP error code being 400 or above. This return code only appears if -f, --fail is used.])

Probably package installation order is non-deterministic here...

Aug 9 2017, 2:23 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
SimonSelg added a comment to T710: qubes-whonix build failure.

In whonix-ws the package is called anon-ws-dns-conf . Yes I'm sure about that. The build log explicitly says "Couldn't resolve host".

Aug 9 2017, 2:11 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
marmarek added a comment to T710: qubes-whonix build failure.

Are you sure about that? According to build log, the issue with whonix-ws is missing 7.0.0 version on server. anon-gw-dns-conf is not installed in whonix-ws

Aug 9 2017, 2:07 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix
SimonSelg added a comment to T710: qubes-whonix build failure.
Aug 9 2017, 1:59 AM · tb-updater, build, Whonix 14, Whonix 13, Qubes, Whonix