Packaged tools for 4.3

I’m not sure how to get the 3isec-dom0-current.repo definition into dnf in dom0. In dom0, I moved 3isec-dom0-current.repo to /etc/yum.repos.d/3isec-dom0-current.repo. I then ran sudo dnf config-manager addrepo --from-file=/etc/yum.repos.d/3isec-dom0-current.repo in dom0. I didn’t see it throw any errors. But when I run sudo qubes-dom0-update 3isec-qubes-task-manager, it says “No match to argument: 3isec-qubes-task-manager”.

That looks fine, and it works for me at this time.
There was some maintenance going on, and perhaps that has affected
you. Suggest you try again.
There is major flaw in current manager - qubes-task info X only
works if the package is installed. This is a known issue - the
alternatives would be for the info call to pull information from
online, or to cache the information text locally and report that. I
have not had time to address this, and dont know which would be better
approach.

I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.

@unman Is 0x7473414DF9A181A45244BDACFDD1B8244731B36C your new GPG key?

I cannot find it on qubes.3isec.org, Team | Qubes OS , or your GitHub profile. I only find it on keyservers. I want to be certain it’s yours.

I ask because I get this error trying to install 3isec-qubes-task-manager:

$ sudo qubes-dom0-update 3isec-qubes-task-manager
Using sys-whonix as UpdateVM for Dom0
Downloading packages. This may take a while…
3isec Qubes Dom0 Repository (updates)           1.2 kB/s | 1.5 kB     00:01
3isec Qubes Dom0 Repository (updates)           1.8 kB/s | 7.7 kB     00:04
Fedora 41 - x86_64                              1.0 kB/s | 4.0 kB     00:04
Fedora 41 - x86_64 - Updates                    3.0 kB/s | 4.0 kB     00:01
Qubes Host Repository (updates)                 1.8 kB/s | 3.2 kB     00:01
Dependencies resolved.

Package                      Arch       Version   Repository              Size

Installing:
3isec-qubes-task-manager     x86_64     1.0-1     3isec-dom0-current      10 k

Transaction Summary

Install  1 Package

Total size: 10 k
Installed size: 12 k
DNF will only download packages for the transaction.
Downloading Packages:
[SKIPPED] 3isec-qubes-task-manager-1.0-1.x86_64.rpm: Already downloaded
error: Verifying a signature using certificate 4B1F400DF25651B53C4141B38B3F30F9C8C0C2EF (unman (Qubes OS signing key) unman@thirdeyesecurity.org):
Certificate 8B3F30F9C8C0C2EF does not contain key 7473414DF9A181A45244BDACFDD1B8244731B36C or it is not valid
Problem opening package 3isec-qubes-task-manager-1.0-1.x86_64.rpm
The downloaded packages were saved in cache until the next successful transaction.
You can remove cached packages by executing ‘dnf clean packages’.
Error: GPG check FAILED

Thank you.

On a Github it says

pub rsa4096 2016-06-25 [SC]
4B1F400DF25651B53C4141B38B3F30F9C8C0C2EF
uid [ unknown] unman (Qubes OS signing key) unman@thirdeyesecurity.org
sub rsa4096 2016-06-27 [S] [expires: 2027-06-30]
sub rsa4096 2016-06-25 [E]

?

I asked about it recently

1 Like

Yes, it is.

https://qubes.3isec.org/tasks.html contains links to keyservers and GitHub.
The key at Team | Qubes OS is the key I use for email.

Check that you have a fresh copy of the key and it is still current. If
your copy has expired you will need to follow the instructions on that
page to copy the key in to dom0 and update the rpm keyring.
If you still get an error:

  1. rpm -q gpg-pubkey --qf '%{NAME}-%{VERSION}-%{RELEASE}\t%{SUMMARY}\n'
    That will give you a list of keys, with output like:
    gpg-pubkey-c8c0c2ef-576dd3b7 unman (Qubes OS signing key)

Then use the identifier to remove the key:
2. rpm -e gpg-pubkey-c8c0c2ef-576dd3b7

Check that the key has been removed by running 1 again.

Check that the key you have in /etc/pki/rpm-gpg/ is up to date. Import that key:
3. rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-unman

If you still have a problem let me know.

I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.

I successfully installed these tools on a 4.3 pre-release last year. I am now trying and failing at installing the tools on a fresh install of stable 4.3.1 with latest Testing Security Updates and Fedora 44 templates . Are they currently working for others from clean install after QSB-116 patches?

In answer to your question, yes, they are working.

I cant help with so little information.
What is the issue that you face, (if you still do have an issue.)

I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.

I managed to get the tool to install but when I run it something goes wrong.

sudo qubes-task install 3isec-qubes-mirage-firewall.x86_64

Installing package:3isec-qubes-mirage-firewall.x86_64

Something went wrong trying to install package: 3isec-qubes-mirage-firewall.x86_64

Check to see if the package was in fact installed.

Thanks@unman for your work and help.

Well done. I should automate this, and reduce the pain.

Thanks for that. Let me know if you hit any other problems or
have suggestions for packages.

I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.

I misspoke. I managed to get the task-manger to install and thought I was out of the woods. I can run it with CLI or GUI and get a list of the packages, but when I try to install one (mirage) It fails to install. with “Something went wrong trying to install package: 3isec-qubes-mirage-firewall.x86_64”

I dont have this issue. Take a look in /var/log/dnf5.log to see what the
issue may be. And. of course, check to see if the qube is installed.

I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.

Yes I checked to make sure the qube was not installed. I tried to install 2 different packages: Mirage and Mullvad with the same results. One other odd behavior I observed on a fresh boot sudo qubes-task list produces list of packages (red text) and sudo qubes-task-gui produces the dialog window with all packages listed. I can successfully repeat this as many times as I like. As soon as I try to install package (Mirage) with either CLI or GUI I get the error and neither CLI or GUI will produce a list of packages until I reboot and then either will produce a list of available packages. CLI error = “Failed to list tasks: name ‘result’ is not defined” I can send you the contents of my /var/log/dn5.log that relates to 3isec files install by PM if you wish

The error you see generally results from an error in qubes-dom0-update.
Can you send me the log file.

Couple of questions:
What are you using for the update qube for dom0?
What is the output if you run in dom0:
sudo qubes-dom0-update 3isec-qubes-mirage-firewall

I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.

I am using the Qubes Update Tool primarily NetVm sys-firewall. I use dom0 XFCE terminal when required.

Here is the output running command sudo qubes-dom0-update 3isec-qubes-mirage-firewall

Note the output in my XFCE terminal was RED TEXT

xxxx@dom0:~$ sudo qubes-dom0-update 3isec-qubes-mirage-firewall
Using sys-firewall as UpdateVM for Dom0
Downloading packages. This may take a while…
Updating and loading repositories:
_[0J Fedora 41 - x86_64 - Updates ???% | 0.0 B/s | 0.0 B | 00m00s0s

Installing:
[32m 3isec-qubes-mirage-firewall[0m x86_64 0:0.9.5-1.fc41 3isec-dom0 4.1 MiB

Transaction Summary:
Installing: 1 package

Total size of inbound packages is 1 MiB. Need to download 0 B.
After this operation, 4 MiB extra will be used (install 4 MiB, remove 0 B).
The operation will only download packages for the transaction.
_[?25l[1/1] 3isec-qubes-mirage-firewall-0:0.9 100% | 0.0 B/s | 0.0 B | 00m00s

[32mAlready downloaded[0m


[1/1] Total 100% | 0.0 B/s | 0.0 B | 00m00s
Complete!
_[?25h’/usr/lib/qubes/qrexec-client-vm dom0 qubes.ReceiveUpdates /usr/lib/qubes/qfile-agent /var/lib/qubes/dom0-updates/packages/*.rpm’ failed with exit code 1!
xxxx@dom0:~$

some output removed on edit to help compact

Here is a copy of the dnf5.log that pertains to the install of 3isec-qubes-task-manager. Note the output in my XFCE terminal was RED TEXT

log entries removed for compactness

In dom0 sudo dnf clean all
restart sys-firewall
then sudo qubes-dom0-update 3isec-qubes-mirage-firewall

I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.