-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Sun, May 03, 2015 at 12:22:41AM +0000, Joonas Lehtonen wrote:
> Hi,
>
> I heavily depend on the fact that source IPs of two distinct VMs do
> never match*.
>
> I noticed that in 3.0-rc1 dispvms do no longer have that property.
>
> Start a dispvm, kill it, start another, will result in the same dispvm
> ID and dispvm IP address.
>
> Is this a bug, or by design? Is it possible to change this behavior to
> match to one in R2 via a config change?
This was a desired change to get rid of global lock for dispvm counter.
DispVM was replaced by Qubes VM ID, which is assigned to all the VMs
anyway.
But I see your point. In addition to the IP problem, it gives some clue
about number of VMs in the system - QID is assigned to first unused
value, so if you see "disp16" it means you have at least 15 other VMs
(maybe more). Not sure how unique this value could be in generic case,
but I guess values like 128 are pretty unique...
If you don't have better ideas, indeed it looks like restoring R2
behaviour here is the best option.
> thanks,
> Joonas
>
> *) If the use case is relevant for you: The property is important
> because tor's isolation depends on the source IP when deciding whether
> something needs to go on a distinct circuit.
>
> btw: DispVM bootup in R3 is great - thanks for that!
Glad to hear :)
- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQEcBAEBAgAGBQJVRXm4AAoJENuP0xzK19csKCsH/0ByFLBVtXlZ1J3IBx4kdq2r
lh7LKRKI7KKjsmapMj2PfvMSoPf/obM/EmVxUHbcwlYsh+kyWiyDTjw8/ufQA3rl
L3woABJCtwDBbgDslNEivui+G4XOt/ibcHX3DwZHpuE4ost3eCDX6SFTMZ3b3MPL
shCQVuQIa9wKZYrjdAJoB9uZwoBdiLB2I/XFnTwJQW1IdmmnUBxmMmHoUcqwSd6U
hHzg11xDTAdBWmFgrKOVGPhtKLA0xt84hn0q5iAndWsee/MLtI2czhtilvdDgkGz
7fOGonRTnQ0SNg6jwMPNilEhAqok2oKCKNMNWAGkVMzdlbY1yhie62gGa3hOzgY=
=yoSo
-----END PGP SIGNATURE-----