Page MenuHomePhabricator

Whonix 15Project
ActivePublic

Members

  • This project does not have any members.
  • View All

Watchers (1)

Recent Activity

Fri, May 29

Patrick added a comment to T993: improve Windows Hosts / macOS wiki mentions.

The The news report [1] link is nowadays broken. It redirects to another page.

Fri, May 29, 3:34 PM · Whonix, Whonix 15, user documentation

Thu, May 28

madaidan added a comment to T993: improve Windows Hosts / macOS wiki mentions.

More points that should be removed:

Thu, May 28, 9:46 PM · Whonix, Whonix 15, user documentation

Sun, May 17

Patrick closed T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on as Resolved.

Awesome!

Sun, May 17, 9:21 PM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Yes, worth it. I guess lots of people are going to try Whonix-Host inside a virtual machine before considering installation on real hardware. That's why I even would like to have ability to run Whonix-Host inside VirtualBox.

Please post new tickets in forums as per:
https://forums.whonix.org/t/abolishing-whonix-phabricator-issue-tracker-moving-issue-tracking-to-forums-migrating-phabricator-whonix-org-to-forums-whonix-org/7112

Sun, May 17, 8:54 PM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode

Sat, May 16

Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

But forgot to add sudo install_package_list+=" debug-misc "...

Sat, May 16, 5:05 PM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode

Fri, May 15

onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Just built 15.0.1.3.6-developers-only

Fri, May 15, 11:42 AM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Great! Will try to build tomorrow and report back... asap :)

Fri, May 15, 1:11 AM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode
Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Please add your build commands to Whonix wiki Dev/Whonix-Host, then I can add suggestion there how to improve these.

Not sure what you mean here?

Fri, May 15, 1:05 AM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

That's probably because of T950. You'd need to remove both:

quiet loglevel=0

I see. But I won't lose time to debug this particular build, I will just try a new one and see if the problem persists. Had some problems with lack of space on the VM I am building with, maybe related. Not worth debugging if it's a one time thing. We'll see.

Fri, May 15, 12:05 AM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode

Thu, May 14

Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Seems I have quite a flexible notion of "asap" :)...

Thu, May 14, 9:11 PM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode
Patrick added a comment to T950: set kernel.printk sysctl to prevent kernel info leaks.
Thu, May 14, 8:58 PM · Debian version 11 codename Bullseye, Whonix 15, security-misc, Whonix
onion_knight2 added a comment to T969: instructions how to burn Whonix-Host ISO image to DVD or USB.

Done, as well as further additions.

Thu, May 14, 4:54 PM · Whonix 15, Whonix-Host, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Seems I have quite a flexible notion of "asap" :)...

Thu, May 14, 4:47 PM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode

Wed, May 13

Patrick added a comment to T969: instructions how to burn Whonix-Host ISO image to DVD or USB.

Added upload access also just now. Please try upload image.

Wed, May 13, 7:25 PM · Whonix 15, Whonix-Host, Whonix
Patrick added a comment to T969: instructions how to burn Whonix-Host ISO image to DVD or USB.

Approved now.

Wed, May 13, 7:15 PM · Whonix 15, Whonix-Host, Whonix
onion_knight2 added a comment to T969: instructions how to burn Whonix-Host ISO image to DVD or USB.

Done. Waiting for approval. Still uncompleted, will add instruction step by step.
I also wanted to add some pictures but I think I don't have sufficient rights...

Wed, May 13, 6:06 PM · Whonix 15, Whonix-Host, Whonix
Patrick added a comment to T969: instructions how to burn Whonix-Host ISO image to DVD or USB.

Yes, by all means. Please do.
Generally, most non-controversial (and this one certainly is) wiki edits can be done without prior asking.

Wed, May 13, 2:00 PM · Whonix 15, Whonix-Host, Whonix
onion_knight2 added a comment to T969: instructions how to burn Whonix-Host ISO image to DVD or USB.

Glad that you liked it!
If you don't mind, I can already start modifying the Wiki page:
http://dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/wiki/Whonix-Host

Wed, May 13, 1:24 PM · Whonix 15, Whonix-Host, Whonix
Patrick added a comment to T969: instructions how to burn Whonix-Host ISO image to DVD or USB.

Excellent!

Wed, May 13, 12:13 PM · Whonix 15, Whonix-Host, Whonix
onion_knight2 added a comment to T969: instructions how to burn Whonix-Host ISO image to DVD or USB.

Warning: Whonix-Host is experimental software and still in early development. It is currently still lacking some core features, such as persistent installation in EFI mode or a working firewall on the Host, and is not yet ready for production, nor intended for end-users, only developers. Please see https://forums.whonix.org/t/whonix-host-developers-only-preview-version-15-0-1-2-7-released/9360 for more information on its development state. Help welcome.

What is Whonix-Host?
Whonix-Host is a complete Operating System provided by Whonix developers specifically designed to run Whonix virtual machines ("Whonix-Gateway" and "Whonix-Workstation").

Wed, May 13, 8:47 AM · Whonix 15, Whonix-Host, Whonix

Tue, May 12

Patrick updated the task description for T993: improve Windows Hosts / macOS wiki mentions.
Tue, May 12, 4:02 PM · Whonix, Whonix 15, user documentation
Patrick triaged T993: improve Windows Hosts / macOS wiki mentions as Normal priority.
Tue, May 12, 3:55 PM · Whonix, Whonix 15, user documentation

Mon, May 11

Patrick triaged T990: whonixcheck tirdad module load as Normal priority.
Mon, May 11, 3:33 PM · Whonix 15, Whonix, whonixcheck
Patrick triaged T989: whonixcheck check systemd journal unit as Normal priority.
Mon, May 11, 3:27 PM · Whonix 15, Whonix, whonixcheck

Apr 28 2020

Patrick renamed T910: anti-forensics / amnesia testing of Whonix-Host in Live mode from amnesia testing of Whonix-Host in Live mode to anti-forensics / amnesia testing of Whonix-Host in Live mode.
Apr 28 2020, 7:03 PM · Whonix 15, Whonix-Host, Whonix

Apr 23 2020

Patrick closed T970: Whonix-Host hash, gpg, signify, torrent, signature creation script as Resolved.

Works fine in 15.0.1.3.2-developers-only.

Apr 23 2020, 9:37 PM · Whonix 15, Whonix, Whonix-Host
Patrick closed T928: install xfce4-power-manager on Whonix Host and Kicksecure Host as Resolved.

xfce4-power-manager is installed on Whonix-Host in 15.0.1.3.2-developers-only.

Apr 23 2020, 9:37 PM · Whonix 15, whonix-libvirt, live-mode, Whonix-Host, Whonix
Patrick closed T986: Whonix-Host livecheck systray broken as Resolved.

Fixed in 15.0.1.3.2-developers-only.

Apr 23 2020, 9:36 PM · Whonix 15, Whonix, Whonix-Host
Patrick added a comment to T950: set kernel.printk sysctl to prevent kernel info leaks.

Setting quiet loglevel=0 in that exact order as per https://github.com/Whonix/security-misc/commit/6485df8126b52a2072824fa442e8d1dd5cb18981 does now hide [sda] Incomplete mode parameter data. However, messages by LKRG are not yet hidden.

Apr 23 2020, 6:40 PM · Debian version 11 codename Bullseye, Whonix 15, security-misc, Whonix
Patrick updated subscribers of T961: fix USB auto mounting bug / document.
Apr 23 2020, 4:59 PM · research, bug, Whonix, Whonix 15
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Great news! I am rebuilding the whole package Host+gw+ws now, excited to test it out! Will report asap.

Apr 23 2020, 4:18 PM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode
Patrick reassigned T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on from Patrick to onion_knight2.
echo "options overlay metacopy=on" > /etc/modprobe.d/overlay.conf 
update-initramfs -u
Apr 23 2020, 1:01 PM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode

Apr 21 2020

onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

That would be OK but this is not my preferred solution. Reason: an unclean shutdown in Whonix installed persistent mode would with a subsequent boot into live mode would result in a failed reboot into Whonix installed live mode.

Apr 21 2020, 8:34 PM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode
Patrick added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Awesome analysis and description!

Apr 21 2020, 6:28 PM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode
Patrick changed the status of T986: Whonix-Host livecheck systray broken from Open to testing-in-next-build-required.

Likely fixed in next build already. Updated, relevant code is here:

Apr 21 2020, 6:25 PM · Whonix 15, Whonix, Whonix-Host
Patrick updated subscribers of T986: Whonix-Host livecheck systray broken.
Apr 21 2020, 5:00 PM · Whonix 15, Whonix, Whonix-Host
Patrick triaged T986: Whonix-Host livecheck systray broken as Normal priority.
Apr 21 2020, 5:00 PM · Whonix 15, Whonix, Whonix-Host
Patrick closed T965: install gvfs by default / fix access LUKS encrypted USB drive with Thunar as Resolved.

Not 100% sure it would also be fixed inside VMs.

Apr 21 2020, 11:01 AM · Whonix 15, Whonix, bug
Patrick closed T929: Whonix XFCE Wallpaper / Background Image as Resolved.
Apr 21 2020, 10:57 AM · Whonix 15, Whonix-Host, Whonix, whonix-xfce-desktop-config
Patrick closed T976: Whonix-Host Low RAM Tests as Resolved.

Excellent work. Thanks for researching this!

Apr 21 2020, 10:56 AM · Whonix 15, Whonix-Host, Whonix
Patrick closed T982: use update-initramfs during installation of Whonix-Host as Resolved.
Apr 21 2020, 10:54 AM · Whonix-Host, Whonix 15, Whonix
onion_knight2 added a comment to T914: Whonix Host Live - enable KVM readonly mode - virt-xml vm-name --edit --disk readonly=on.

Some progress made as of Whonix-Host 15.0.1.2.7:

Apr 21 2020, 3:15 AM · Whonix 15, Whonix-Host, whonix-libvirt, Whonix, live-mode
onion_knight2 added a comment to T929: Whonix XFCE Wallpaper / Background Image.

As of Whonix-Host 15.0.1.2.7 each environment (Host, gw, ws) has its own background color.
Should we close this ticket?

Apr 21 2020, 1:39 AM · Whonix 15, Whonix-Host, Whonix, whonix-xfce-desktop-config
onion_knight2 added a comment to T976: Whonix-Host Low RAM Tests.

Do we need more tests or can we close this ticket?

Apr 21 2020, 1:37 AM · Whonix 15, Whonix-Host, Whonix
onion_knight2 added a comment to T982: use update-initramfs during installation of Whonix-Host.

Fixed.
https://forums.whonix.org/t/whonix-host-operating-system/3931/261

Apr 21 2020, 1:37 AM · Whonix-Host, Whonix 15, Whonix
onion_knight2 added a comment to T965: install gvfs by default / fix access LUKS encrypted USB drive with Thunar.

Also, just tried it on Whonix-Host 15.0.1.2.7. It works.

Apr 21 2020, 1:35 AM · Whonix 15, Whonix, bug

Apr 16 2020

Patrick added a comment to T950: set kernel.printk sysctl to prevent kernel info leaks.

Even kernel parameter quiet loglevel=3 rd.systemd.show_status=auto rd.udev.log_priority=3
(from https://wiki.archlinux.org/index.php/Silent_boot)
does not hide [sda] Incomplete mode parameter data.

Apr 16 2020, 4:02 PM · Debian version 11 codename Bullseye, Whonix 15, security-misc, Whonix
Patrick updated the task description for T911: xfce theming.
Apr 16 2020, 3:34 PM · whonix-xfce-desktop-config, Whonix 15, Whonix
Patrick renamed T946: test sdwdate apparmor profile and remove complain mode from test sdwdate apparmor profile and set to complain mode to test sdwdate apparmor profile and remove complain mode.
Apr 16 2020, 3:32 PM · sdwdate, Whonix 15, Whonix
Patrick changed the status of T966: fix pkexec from Open to testing-in-next-build-required.

https://github.com/Whonix/security-misc/commit/72be31e870057b035651c1b5a7e9a9db149e9d25
https://github.com/Whonix/security-misc/commit/442931529121e9e402e7ac56e27df3dcec43167b
https://github.com/Whonix/security-misc/commit/b3ce18f0f9f1da0552a4a1bd882a5b5dda13626e
https://github.com/Whonix/security-misc/commit/8851c9ed29e79d2ef5df9c7b7086878e69b90bd4

Apr 16 2020, 3:29 PM · bug, Whonix 15, Whonix