So I need a disposable standard debian 11 template.
To do so I created a clone of debian-11 template and named it debian-11-tmp-dvm.
Then I create an AppVM based on that template and configure it as disposable.
In my debian-11-tmp-dvm template the apt source is set on the tor+http address for qubes-r4 list file.
I have already installed the apt-transport-tor packet and I can update normally in the template.
But when I am trying to install software in my disp1234 AppVM I have a timeout error on socks5h 127.0.0.1:9050…
I always keep debian-11 template as ‘stock’ and never modify them but clone them for each need to modify them.
I found the same issue when using a debian-11-minimal template.
In the scenario of an disposable AppVM based on debian-11-minimal template with Firefox installed the problem seems to be not…in my disp1234 I can install software without this timeout error on qubes tor repo…
I have been searching this issue long enough to come here and ask for help…
If anyone can advise on where to look and what to verify, I will be glad.
I’d try to set sys-whonix as netvm for dtvm and tbdvm, than disable all onion repositories and enable clear net repositories in the dtvm and would give it a try installing software in tbdvm.
Sorry to hear, but it’s not clear from your response if you disabled onion repositories and enabled http only. That helped me when I had such an issue, but your is probably different, it looks.
DTVM stands for Disposable Template Virtual Machine (debian-11-tmp-dvm) and tbdvm Template Based Disposable Virtual Machine (disp1234), apologize for not being clear.
I hope someone else will have a better suggestion.
apt-transport-tor relies on there being a working Tor on the qube.
That’s why you see the reference to port 9050.
You can do this but it is not necessary.
If you want to update over Tor, you don’t need to use tor+http. Just use
sys-whonix as the netVM, so that all traffic runs over Tor. You can
either keep the vanilla https definitions and connect to the standard
repositories, or change to the onion repository.
I never presume to speak for the Qubes team.
When I comment in the Forum or in the mailing lists I speak for myself.