New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add template-related info to qubesdb #1101

Closed
marmarek opened this Issue Aug 4, 2015 · 2 comments

Comments

Projects
None yet
2 participants
@marmarek
Member

marmarek commented Aug 4, 2015

Two new keys:

  1. /qubes-vm-persistence:
    • full - standalone / template
    • rw-only - template based (it's reference to /rw, since it isn't only /home)
    • none - DispVM
  2. /qubes-base-template, which would contain name of template on which the VM is based (in case of TemplateBasedVMs), or empty string in case of standalone VM/template. After some consideration, VM already has ability to get the template name (for example from logs), so this will not pose additional
    data leak.

Discussion and reasoning here:
https://groups.google.com/d/msgid/qubes-devel/20150802204109.GK3332%40mail-itl

@adrelanos

This comment has been minimized.

Show comment
Hide comment
@adrelanos

adrelanos Sep 3, 2015

Member

Looks like there is a bug or derivation from the above plan? Just now checked. Running qubesdb-read /qubes-vm-persistence in a DispVM returns rw-only rather than none as suggested above.

Member

adrelanos commented Sep 3, 2015

Looks like there is a bug or derivation from the above plan? Just now checked. Running qubesdb-read /qubes-vm-persistence in a DispVM returns rw-only rather than none as suggested above.

marmarek added a commit to marmarek/old-qubes-core-admin that referenced this issue Sep 3, 2015

@marmarek

This comment has been minimized.

Show comment
Hide comment
@marmarek

marmarek Sep 3, 2015

Member

On Thu, Sep 03, 2015 at 10:56:04AM -0700, Patrick Schleizer wrote:

Looks like there is a bug or derivation from the above plan? Just now checked. Running qubesdb-read /qubes-vm-persistence in a DispVM returns rw-only rather than none as suggested above.

Oops, indeed. Fixed.

Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?

Member

marmarek commented Sep 3, 2015

On Thu, Sep 03, 2015 at 10:56:04AM -0700, Patrick Schleizer wrote:

Looks like there is a bug or derivation from the above plan? Just now checked. Running qubesdb-read /qubes-vm-persistence in a DispVM returns rw-only rather than none as suggested above.

Oops, indeed. Fixed.

Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?

adrelanos added a commit to Whonix/whonixcheck that referenced this issue Sep 3, 2015

refactoring, ported from old 'qubesdb-read /qubes-vm-updateable' to n…
…ew (QubesOS/qubes-issues#1101) more readable 'qubesdb-read /qubes-vm-persistence'
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment