Schenker XMG NEO 15 (M19)

---
layout:
  'hcl'
type:
  'notebook'
hvm:
  'yes'
iommu:
  'yes'
slat:
  'yes'
tpm:
  'unknown'
remap:
  'yes'
brand: |
  SchenkerTechnologiesGmbH
model: |
  XMG NEO (M19, RTX 2060)
bios: |
  N.1.53
cpu: |
  Intel(R) Core(TM) i7-9750H CPU @ 2.60GHz
cpu-short: |
  FIXME
chipset: |
  Intel Corporation 8th Gen Core Processor Host Bridge/DRAM Registers [8086:3ec4] (rev 07)
chipset-short: |
  FIXME
gpu: |
  Intel Corporation CoffeeLake-H GT2 [UHD Graphics 630] [8086:3e9b] (prog-if 00 [VGA controller])
  NVIDIA Corporation TU106M [GeForce RTX 2060 Mobile] [10de:1f11] (rev a1) (prog-if 00 [VGA controller])
gpu-short: |
  FIXME
network: |
  Realtek Semiconductor Co., Ltd. RTL8111/8168/8411 PCI Express Gigabit Ethernet Controller (rev 15)
  Intel Corporation Wireless-AC 9260 (rev 29)
memory: |
  16241
scsi: |
  CT1000MX500SSD4  Rev: 023 
usb: |
  3
versions:

- works:
    'FIXME:yes|no|partial'
  qubes: |
    R4.1
  xen: |
    4.14.3
  kernel: |
    5.15.14-1
  remark: |
    FIXME
  credit: |
    FIXAUTHOR
  link: |
    FIXLINK

---

Remarks

After initial system setup everything (I use/need) worked out-of-the-box with 4.0.4 and all release candidates of 4.1. Networking, sleep, video, all work fine.

As for my customization, nowadays I use Debian minimal templates as default template for basically everything meaning that I build my own sys-* and app-* qubes on the minimal templates. With app-* qubes I mean that I have dedicated template for my major apps I often use. besides that I have templates with additional epositories as snapcraft in case I quickly need an app for a short time e.g. for testing. Usually those have a rather short lifetime. In case the start to do I migrate to a dedicated template. Again, everything works even suspend and one must even not qvm-kill sys-net as wifi just reconnects after sleep. :smiley:

Going forward I would love to make “real” minimal templates based on Gentoo. I used Gentoo for years before I moved to Qubes and I love it still. With real minimal I refer to e.g. minimal kernels. There is also a huge unnecessary attack surface. Only issue with this concept is, that one goes nuts due to compute limitations. Just imagine to update and compile updates for 30+ templates. This would take ages to do so… I think only feasible option would be a dedicated build machine and heavy utilization of distcc, with all its cons. Unfortunately does this also prevent me from the ideal state in which the entire system is based on musl, totally avoiding glibc. So, my philosophy would be to remove complexity even further by minimal kernel, no systemd, no gcc, etc. I hope this makes sense… Let’s see if and when I find the time for this experiment. :smiley:

Hope this helps and sorry for taking so much time to upload this HCL - mea culpa!

This is the notebook: https://download.schenker-tech.de/package/xmg_neo17xne17m19/

UPDATE: I did not alter the BIOS (yet). No coreboot or alternative used. Currently I use the build in secureboot with work out-of-the-box as well. One can deploy keys and sign the grub and xen *.efi images which is for my current threat model sufficient while not perfect…

Attachments

1 Like

Thank you @voidstar for your HCL report, which is online now.

1 Like

Excellent. Thanks. Here one can find a detailed assessment of the notebook. Unfortunately in German (company is German as well).

English:

I was just thinking… another interesting feature for privacy focused people is that in BIOS one can disable hardware as webcam, wifi and other possibly privacy impacting features which is also pretty nice for a Qubes user I imagine… :slight_smile:

1 Like