To upgrade Insurgo Privacybeast to 4.1 or not?

Update for late upgraders (No. Internal upgrade from 4.0 to 4.1 is still not recommended on my side, unfortunately. Hopefully, next 4.1-> 4.2 upgrade will work out of the box, but this is not the case for 4.0 to 4.1 even today with fixes still happening where 4.2 is now in the works).

So time to practice your backup/restore mental muscle and template specialization skills, reapplying some tweaks manually.

Upstream instructions have been updated and clarified a lot since the previous discussions:

  1. Backup of Qubes OS How to back up, restore, and migrate | Qubes OS
  2. Download Qubes ISO and Qubes ISO detached signature on previously prepared USB thumb drive (EXT3/EXT4 partition required). (right-click, “save link as…” (or equivalent) on mounted USB thumb drive passed to your qube). Verify integrity on actual Heads firmware by attempting Options->Boot Options-> Boot from USB (should verify ISO and propose boot options)
    1. https://ftp.qubes-os.org/iso/Qubes-R4.1.1-x86_64.iso
    2. https://ftp.qubes-os.org/iso/Qubes-R4.1.1-x86_64.iso.asc
  3. Download x230-htop-maximized latest firmware (right-click link in artifacts, “save link as…” or equivalent), verify hashes as instructed putting rom alongside Qubes iso and Qubes iso detached signature on a EXT3/EXT4 USB thumb drive following Step 1 - Downloading Heads - Heads - Wiki
  4. Make sure you have a copy of your GPG public key on that USB thumb drive as well to be able to inject it back after manually flashing to maximized board.
  5. Follow manual flashrom instruction to upgrade once from Recovery Shell from legacy to maximized firmware following Upgrading Heads - Heads - Wiki
  6. Install Qubes 4.1: Step 4 - Installing Qubes and other OSes - Heads - Wiki
  7. Depending of if you inject back your public key or apply Re-Ownership, follow appropriate steps Step 3 - Configuring-Keys - Heads - Wiki

Be cautious, specially with step 3 above, making sure your full 12mb rom image has good checksums. You then have to manually flash once from the revocery whell, to migrate from legacy boars to maximized boards, with mount-usb and flashrom -p internal -w /media/heads-x230-hotp-maximized-version-commit_id.rom as documented. DO NOT USE MENUS TO MIGRATE FROM LEGACY BOARDS TO MAXIMIZED BOARDS. Internal upgrades can then be flashed internally through the menus, if you already are using a maximized board.

Notes

[connection]
ethernet.cloned-mac-address=stable
3 Likes