Qubes OS updates Weekly Review - Y2024-W41

Introduction

Weekly review of new packages uploaded to Qubes OS repositories. Notes on how it is prepared and what resources are used to write this newsletter is available in previous versions .

Alphabetically sorted list of new packages uploaded to Qubes OS repositories
kernel-6.6.54-1.qubes.fc37.x86_64.rpm
kernel-6.6.54-1.qubes.fc41.x86_64.rpm
kernel-devel-6.6.54-1.qubes.fc37.x86_64.rpm
kernel-devel-6.6.54-1.qubes.fc41.x86_64.rpm
kernel-latest-6.11.2-1.qubes.fc37.x86_64.rpm
kernel-latest-6.11.2-1.qubes.fc41.x86_64.rpm
kernel-latest-devel-6.11.2-1.qubes.fc37.x86_64.rpm
kernel-latest-devel-6.11.2-1.qubes.fc41.x86_64.rpm
kernel-latest-modules-6.11.2-1.qubes.fc37.x86_64.rpm
kernel-latest-modules-6.11.2-1.qubes.fc41.x86_64.rpm
kernel-latest-qubes-vm-6.11.2-1.qubes.fc37.x86_64.rpm
kernel-latest-qubes-vm-6.11.2-1.qubes.fc41.x86_64.rpm
kernel-modules-6.6.54-1.qubes.fc37.x86_64.rpm
kernel-modules-6.6.54-1.qubes.fc41.x86_64.rpm
kernel-qubes-vm-6.6.54-1.qubes.fc37.x86_64.rpm
kernel-qubes-vm-6.6.54-1.qubes.fc41.x86_64.rpm
libqrexec-utils2_4.3.0-1+deb12u1_amd64.deb
libqrexec-utils2_4.3.0-1+deb13u1_amd64.deb
libqrexec-utils2_4.3.0-1+jammy1_amd64.deb
libqrexec-utils2-dbgsym_4.3.0-1+deb12u1_amd64.deb
libqrexec-utils2-dbgsym_4.3.0-1+deb13u1_amd64.deb
libqrexec-utils-dev_4.3.0-1+deb12u1_amd64.deb
libqrexec-utils-dev_4.3.0-1+deb13u1_amd64.deb
libqrexec-utils-dev_4.3.0-1+jammy1_amd64.deb
python3-qrexec_4.3.0-1+deb12u1_amd64.deb
python3-qrexec_4.3.0-1+deb13u1_amd64.deb
python3-qrexec_4.3.0-1+jammy1_amd64.deb
qubes-core-dom0-4.3.8-1.fc41.noarch.rpm
qubes-core-dom0-4.3.9-1.fc41.noarch.rpm
qubes-core-qrexec_4.3.0-1+deb12u1_amd64.deb
qubes-core-qrexec_4.3.0-1+deb13u1_amd64.deb
qubes-core-qrexec-4.3.0-1.fc39.x86_64.rpm
qubes-core-qrexec-4.3.0-1.fc40.x86_64.rpm
qubes-core-qrexec-4.3.0-1.fc41.x86_64.rpm
qubes-core-qrexec_4.3.0-1+jammy1_amd64.deb
qubes-core-qrexec-dbgsym_4.3.0-1+deb12u1_amd64.deb
qubes-core-qrexec-dbgsym_4.3.0-1+deb13u1_amd64.deb
qubes-core-qrexec-devel-4.3.0-1.fc39.x86_64.rpm
qubes-core-qrexec-devel-4.3.0-1.fc40.x86_64.rpm
qubes-core-qrexec-devel-4.3.0-1.fc41.x86_64.rpm
qubes-core-qrexec-dom0-4.3.0-1.fc41.x86_64.rpm
qubes-core-qrexec-libs-4.3.0-1.fc39.x86_64.rpm
qubes-core-qrexec-libs-4.3.0-1.fc40.x86_64.rpm
qubes-core-qrexec-libs-4.3.0-1.fc41.x86_64.rpm
qubes-core-qrexec-vm-4.3.0-1.fc39.x86_64.rpm
qubes-core-qrexec-vm-4.3.0-1.fc40.x86_64.rpm
qubes-core-qrexec-vm-4.3.0-1.fc41.x86_64.rpm
qubes-core-qrexec-vm-selinux-4.3.0-1.fc39.x86_64.rpm
qubes-core-qrexec-vm-selinux-4.3.0-1.fc40.x86_64.rpm
qubes-core-qrexec-vm-selinux-4.3.0-1.fc41.x86_64.rpm
qubes-vm-qrexec-4.3.0-1-x86_64.pkg.tar.zst

Highlights

  • Supports of UUID is added to Admin API to target VMs.
  • Better support for additional policy directories (including temporal)

Details

In addition to the usual minor fixes and patches:

  • core-admin v4.3.8 & v4.3.9 (r4.3)
    . Support of UUID (Universally Unique Identifier) is added. Even if you delete a VM and recreate a new one with the same name, its UUID is guarantied to be unique. qrexec policy supports uuid:<UUID> format as an alternative to qube name.
    . Fixes related to Fedora 41 support
    . Libvirt related fixes

  • core-qrexec v4.3.0 (r4.3)
    . It is possible to put temporal policy files at /run/qubes/policy.d. This is specifically useful for DispVMs.
    . Core parts of UUID

  • linux-kernel v6.6.54-1, v6.11.2-1-latest, (r4.2 & r4.3)
    weekly Linux Kernel updates. As usual, refer to Greg Kroah-Hartman announcement on lwn.net to find out more about the changes.

Epilogue

Support for UUID is not yet added to most of end-user command line (qvm-*) and GUI utilities (Qubes Manager). I guess this will be added in forthcoming weeks.

12 Likes

The new temporary qrexec policy directory is in /run instead of /etc.

Original post is corrected. Thanks.

2 Likes

Please confirm: “temporal” was supposed to be “temporary”?
(just want to make sure that they are not adding new “time of day” policy directives :slight_smile:

1 Like

Exactly. Temporary. Not stored in hard drive.