Page MenuHomePhabricator

Whonix 15Project
ActivePublic

Members

  • This project does not have any members.

Watchers (1)

Recent Activity

Aug 16 2019

Patrick updated the task description for T911: xfce theming.
Aug 16 2019, 4:22 PM · Whonix, Whonix 15

Jul 22 2019

HulaHoop closed T769: Add LUKS container GUI or CLI utility by default as Resolved.
Jul 22 2019, 3:04 AM · Whonix 15, Debian version 10 codename Buster
HulaHoop added a comment to T769: Add LUKS container GUI or CLI utility by default.

Yes Zulucrypt included and functional on KVM 15. However fixes for both zulucrypt and tomb haven't made it into Buster from what I've tested. Zulucrypt has a tomb plugin to open Tomb files too.

Jul 22 2019, 3:03 AM · Whonix 15, Debian version 10 codename Buster

Jul 16 2019

marmarek added a comment to T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
In T913#18744, @Patrick wrote:

Do you see any issues with "create home directory on first login" in Qubes?

Jul 16 2019, 1:07 AM · whonix-base-files, live-mode, Whonix 15, Whonix
Patrick added a comment to T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.

Can you give some more context here?

Jul 16 2019, 12:42 AM · whonix-base-files, live-mode, Whonix 15, Whonix

Jul 15 2019

marmarek added a comment to T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.

Can you give some more context here? Is it the problem that user is created too early (before /etc/skel is fully populated)? Or is it a problem that it's created at all? Should there be a difference between Qubes and non-Qubes case?

Jul 15 2019, 11:58 PM · whonix-base-files, live-mode, Whonix 15, Whonix
Patrick updated the task description for T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
Jul 15 2019, 6:23 PM · whonix-base-files, live-mode, Whonix 15, Whonix

Jul 14 2019

Patrick updated the task description for T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
Jul 14 2019, 9:29 AM · whonix-base-files, live-mode, Whonix 15, Whonix
Patrick updated subscribers of T913: bug: not all files form /etc/skel are copied to /home/user / create user "user" at boot time.
Jul 14 2019, 8:42 AM · whonix-base-files, live-mode, Whonix 15, Whonix

Jul 8 2019

Patrick closed T631: re-enable tor-controlport-filter.service systemd hardening as Resolved.
Jul 8 2019, 9:49 PM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)
Patrick added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

Removed a few. Would not start without openat, so kept.

Jul 8 2019, 9:49 PM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)
madaidan added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

Yay, we have ProtectSystem=strict now.

Jul 8 2019, 8:30 PM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)
Patrick added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

Yay, we have ProtectSystem=strict now.

Jul 8 2019, 1:06 AM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)
Patrick added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

Can we exclude ExecStartPre=/usr/lib/onion-grater-merger from systemd hardening?

Jul 8 2019, 12:53 AM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)

Jul 7 2019

Patrick added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

Error back after reboot.

Jul 7 2019, 11:50 PM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)

Jul 6 2019

madaidan added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

https://github.com/Whonix/onion-grater/blob/master/lib/systemd/system/onion-grater.service currently works without ReadWritePaths. So let's not add?

Jul 6 2019, 4:23 PM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)
Patrick added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

https://github.com/Whonix/onion-grater/blob/master/lib/systemd/system/onion-grater.service currently works without ReadWritePaths. So let's not add?

Jul 6 2019, 1:03 PM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)

Jul 4 2019

madaidan added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

It's a file, not a folder.

Jul 4 2019, 5:09 PM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)
Patrick added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

https://github.com/Whonix/onion-grater/commit/8480cff304ea019b25dc49d91672e7c3f8599a07

Jul 4 2019, 7:59 AM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)
Patrick added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

It's a file, not a folder. Nothing in the code of
/usr/lib/onion-grater-merger writes to /usr/lib/onion-grater-merger.

Jul 4 2019, 7:41 AM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)

Jul 3 2019

madaidan added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

I just re-read the error message. Try adding

Jul 3 2019, 5:10 PM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)
madaidan added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

That's weird. Onion-grater is trying to write to somewhere that's being mounted read-only by systemd.

Jul 3 2019, 4:56 PM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)

Jul 1 2019

Patrick added a comment to T631: re-enable tor-controlport-filter.service systemd hardening.

Merged your changes.

Jul 1 2019, 10:11 AM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)

Jun 27 2019

marmarek added a comment to T923: Some texts on whonix connection wizard are truncated.

I see.
BTW it's certainly about fonts. here you can select whonix_firstrun-whonix-14-firstrun-20180915 from the dropdown above the screenshot (click eye icon at the right) and slide vertical bar to see old and new version.

Jun 27 2019, 2:47 PM · anon-connection-wizard, Whonix, Whonix 15
Patrick added a comment to T923: Some texts on whonix connection wizard are truncated.

marmarek (Marek Marczykowski-Górecki):

Is there a reason for fixed geometry of those widgets, instead of letting Qt figure it out based on the content?

Jun 27 2019, 2:40 PM · anon-connection-wizard, Whonix, Whonix 15
marmarek added a comment to T923: Some texts on whonix connection wizard are truncated.

Maybe different fonts installed? Is there a reason for fixed geometry of those widgets, instead of letting Qt figure it out based on the content? I suppose there may be more problems like this in the future. Especially if proper HiDPI support will come into play...

Jun 27 2019, 2:34 PM · anon-connection-wizard, Whonix, Whonix 15
Patrick added a project to T923: Some texts on whonix connection wizard are truncated: anon-connection-wizard.

I have no idea why this started happening without changes. Perhaps due to underlying libraries changes. Anyhow, fixed in git master.

Jun 27 2019, 2:15 PM · anon-connection-wizard, Whonix, Whonix 15
marmarek created T923: Some texts on whonix connection wizard are truncated.
Jun 27 2019, 1:26 PM · anon-connection-wizard, Whonix, Whonix 15
Patrick added a comment to T912: qubes integration tools missing.

Work for me too in new build https://forums.whonix.org/t/qubes-whonix-15-templatevms-debian-buster-based-4-0-1-201906232114-testers-wanted/7601

Jun 27 2019, 10:53 AM · Whonix, Qubes
Patrick added a comment to T769: Add LUKS container GUI or CLI utility by default.

Does this work in https://forums.whonix.org/t/whonix-virtualbox-15-0-0-3-3-debian-buster-based-testers-wanted/7604? @HulaHoop

Jun 27 2019, 10:42 AM · Whonix 15, Debian version 10 codename Buster
Patrick added a comment to T869: Install Firejail by default inside Whonix.

Implementation looks good enough for now.

Jun 27 2019, 10:34 AM · Whonix 15, firejail, Whonix
Patrick added a comment to T883: configure Qubes-Whonix XFCE default start menu entries (whitelisted appmenus).

Seems ok after full removal and re-creation.

Jun 27 2019, 10:31 AM · Whonix 15, Whonix, qubes-template-whonix

Jun 25 2019

madaidan added a comment to T869: Install Firejail by default inside Whonix.

GUI isolation is very important, no?

Jun 25 2019, 10:43 PM · Whonix 15, firejail, Whonix
Patrick added a comment to T869: Install Firejail by default inside Whonix.

Xpra is only used for GUI isolation.

Jun 25 2019, 3:00 PM · Whonix 15, firejail, Whonix

Jun 24 2019

madaidan added a comment to T869: Install Firejail by default inside Whonix.

The problem is, xpra (actually xpra | xserver-xephyr | xvfb) isn't in the list of Recommends: of the firejail package by accident. We don't really know the rationale of that. Could be an optional dependency and without it, some things someone who knows firejail who is happy to find it installed would wonder why it actually does not work.

Jun 24 2019, 8:34 PM · Whonix 15, firejail, Whonix
Patrick edited projects for T631: re-enable tor-controlport-filter.service systemd hardening, added: Whonix 15; removed Whonix 16.
Jun 24 2019, 3:49 PM · Whonix 15, Whonix, enhancement, systemd, onion-grater (Control Port Filter Proxy)
Patrick updated subscribers of T921: Installing git-all will delete some Whonix packages .

runit-sysv is incompatible with Whonix and Qubes Debian template. Even sudo apt install runit-sysv --no-install-recommends would uninstall some Whonix or Qubes packages.

Jun 24 2019, 12:52 AM · Whonix
Patrick updated subscribers of T921: Installing git-all will delete some Whonix packages .

git-all also breaks Qubes Debian buster template. @marmarek

Jun 24 2019, 12:42 AM · Whonix
Patrick added a comment to T921: Installing git-all will delete some Whonix packages .

Another workaround with full git-all functionality that does not break Whonix:

Jun 24 2019, 12:37 AM · Whonix
Patrick added a comment to T921: Installing git-all will delete some Whonix packages .

Another workaround:

Jun 24 2019, 12:32 AM · Whonix
Patrick added a comment to T921: Installing git-all will delete some Whonix packages .

Workaround:
While this should be fixed, note, meanwhile the following works perfectly well for general use of git (I did not ever had any situation where I was missing any features):

Jun 24 2019, 12:30 AM · Whonix
Patrick added a project to T922: Tor-Control-Panel has extra bridge (snowflake) feature which are missed in ACW & normal TBB: anon-connection-wizard.
Jun 24 2019, 12:21 AM · anon-connection-wizard, python, Whonix
Patrick added a project to T922: Tor-Control-Panel has extra bridge (snowflake) feature which are missed in ACW & normal TBB: python.
Jun 24 2019, 12:20 AM · anon-connection-wizard, python, Whonix
TNTBOMBOM created T922: Tor-Control-Panel has extra bridge (snowflake) feature which are missed in ACW & normal TBB.
Jun 24 2019, 12:10 AM · anon-connection-wizard, python, Whonix
TNTBOMBOM edited projects for T921: Installing git-all will delete some Whonix packages , added: Whonix 15; removed Whonix.
Jun 24 2019, 12:05 AM · Whonix

Jun 23 2019

marmarek added a comment to T883: configure Qubes-Whonix XFCE default start menu entries (whitelisted appmenus).

How have you created sys-whonix? Default applications list is copied from template only at VM creation time. If you modify it (using VM settings for example), or just switch template, it isn't re-copied from template (it would break user's changes).

Jun 23 2019, 12:57 PM · Whonix 15, Whonix, qubes-template-whonix
Patrick added a comment to T883: configure Qubes-Whonix XFCE default start menu entries (whitelisted appmenus).

sudo journalctl -f in dom0 does not show anything when running qvm-sync-appmenus whonix-gw-15 in dom0.

Jun 23 2019, 12:21 PM · Whonix 15, Whonix, qubes-template-whonix
Patrick added a comment to T883: configure Qubes-Whonix XFCE default start menu entries (whitelisted appmenus).

QVMM applications tab looks good btw. Just the default applications listed in Qubes start menu (without ever using QVMM applications tab) is not properly populated.

Jun 23 2019, 12:19 PM · Whonix 15, Whonix, qubes-template-whonix

Jun 21 2019

marmarek added a comment to T883: configure Qubes-Whonix XFCE default start menu entries (whitelisted appmenus).

It works for me (checked with qubes-template-whonix-gw-15-4.0.1-201906201340).

Jun 21 2019, 4:18 AM · Whonix 15, Whonix, qubes-template-whonix
marmarek added a comment to T912: qubes integration tools missing.

I cannot reproduce. I've installed qubes-template-whonix-15-4.0.1-201905241112, updated it with qubes testing repository enabled and I see all the actions available in thunar.
But I do see some warnings on thunar's stderr, like this:

(Thunar:27375): Gtk-WARNING **: 01:41:41.317: Refusing to add non-unique action 'uca-action-1507455450991127-4' to action group 'ThunarActions'

Looks like actions are added multiple times to /etc/xdg/Thunar/uca.xml, which is later copied to /home/user/.cnfig/Thunar/uca.xml. Relevant code in https://github.com/QubesOS/qubes-core-agent-linux/blob/master/debian/qubes-core-agent-thunar.postinst

Jun 21 2019, 3:50 AM · Whonix, Qubes