Hi, when I encountered a problem with connecting my adb-enabled phone to a VM through sys-usb, I read that I could attach the USB controller directly to the VM that would talk to the phone, which worked with the no-strict-reset=true option. My understanding of the security issue with that option is that the qube with the attached devices shouldn’t be shutdown without shutting down the whole system (is this correct?), so I disabled sys-usb’s autostart and rebooted.
I was then able to use my VM to handle my phone, but I discovered that my SD card controller (and the card in it) was connected to dom0! This didn’t happen with the USB controllers, and as described here USB qubes | Qubes OS it was configured during install with the rd.qubes.hide_all_usb option set in /etc/default/grub. Is there some way to similarly disable the SD controller from dom0?
Lastly, since it’s just a block device that I didn’t mount, is it worth nuking my system and reinstalling qubes?