Permissions dom0 broken

I messed up my policies and permissions because I made the mistake of again trying to modify things that shouldn’t be modified.

I tried to change the policy and permissions surrounding copy and paste in dom0 which didn’t work, but then after I didn’t remove the stuff that I tried to change and now there’s an issue with dom0, permissions, and I’m guessing maybe a little bit of policies but mainly permissions.

when I go to update or even open certain apps like feather app vm for example, it will say something about update connect denied syswhonix-dom0

then notifications will flash about whonix gateway needs to be on to perform any updates make sure that whonix gateway exists… it exists

it basically isn’t working because dom0 or something happened where the permissions im suppsoed to have are non existent i used two different AIs to try to reset permissions and policies and they did i know it worked, but the permissions will not reset and the policies won’t matter as long as the permissions surrounding them won’t change.

please help me for I am trying to configure my pi 4 and marauder and this is getting in the way BIG TIME

please help, ill be super good and not mess with dom0 permissions and policies anymore.

i dont trust nonpaid versions of chat gpt and grok telling me to reset with a back up i feel like chat gpt is trying to sabotage me because ive been cursing at it so much. like ill go to back up after reinstalling and itll just be a blank 010101 picture of a giant middle finger.

thanks

You use kicksecure or whonix workstation? it’s well known issue, even documented by kicksecure and whonix themself’s.

whonix, mainly all based off of debian 13 xfce and whonix workstation 18, variations of the two with a sys-vpn-mullvad-vpn with the debian and sys whonix with the workstation, and sometimes combined

its mainly these errors combined with when i tried to change the clipboard settings it said denied as well:

denied qubeswindowiconupdater from mullvad to dom0,
denied qubesnotification from feather to dom0
deniedsdwdateguiconnectcheck from feather to sys whonix ,
denied qubesnotificationfrom feather to dom 0

Just to verify… is it possible that you put a syntax error in one of your policy files?

Any error is treated as “No valid policy” which means no permission for anything.

The editors described in the documentation prevent saving of invalid files.

If you have any doubt, try using one of them to open and re-save your modified files.

Whonix workstation based appvm should be connected via appvm based on whonix gateway for network access.

Easier way is to restore policy to default if you have backup or by copy from fresh installation, if you know which one you mess up.

qubeswindowiconupdater - related to gui.
qubesnotificationfrom - related to prevent action that should be allowed, because dom0 handle notification (you can read more in documentation)

deniedsdwdateguiconnectcheck - Whonix 18 + Denied sdwdate. ConnectCheck - #3 by adrelanos

Also, try to read this:

  1. How to edit a policy — Qubes OS Documentation
  2. How to use the Qubes Admin Policies/API despite the lack of documentation - WIP

I’m unsure and afraid to give you advice what to edit in policies to fix it back, lets wait for unman or someone with his level of knowledge to join this topic.

@ilikeitinmybackdoor please keep the language professional. Profanity is now not acceptable here

1 Like

wait! What? Must be a typo :joy:

3 Likes

LOL. Obviously a typo. :joy:

4 Likes