-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Hi all
Adding to the reports about the Thinkpad X1 Carbon 4th gen (20FB), here are my
experiences with the ThinkPad X1 Yoga 20FQ005UGE:
## TL;DR
Qubes OS R3.1 works in CSM mode but the graphics becomes unusable after
suspending, switching to another vty or changing any graphics option. Some
workarounds where required for Grub and the NVMe SSD.
Qubes OS R3.2 can not be installed directly (neither in native UEFI nor CSM).
When doing an in-place upgrade from R3.1 to R3.2, only the 4.1 kernel boots
and can be used to upgrade to 4.8 which fixes the graphics issues.
I have been testing with Qubes OS R3.2 for one month and am really happy with
it. Works for me :) Awesome work!
## Long version
The graphics problems I experienced where already described here:
https://groups.google.com/forum/#!msg/qubes-users/QOINoTl1aXc/2dXut2SrBAAJ
### Qubes OS R3.1 installation
Installer finished but after the reboot Grub is not able to find its /boot.
Same as the initial post here:
https://www.reddit.com/r/Qubes/comments/4vqb3y/grub_fails_to_boot
`ls` only shows: (hd0)
So, no partitions.
Possible fix: Boot into rescue mode of the installer and install /boot and
Grub onto a USB thumb drive. I used the handy anti-evil-maid-install script
for this task which only needed to be slightly modified (attached).
Not needed when using Grub from R3.2.
### Qubes OS R3.2 installation
The platform resets when booting Linux 4.4.31 from R3.2 with CSM as described
in
https://www.reddit.com/r/Qubes/comments/4vqb3y/grub_fails_to_boot/ and
https://groups.google.com/forum/#!topic/qubes-users/mOlHA2KhzLE
When debugging is enabled, you can see that Xen boots just fine and one of the
last entries is that Xen starts dom0
* i915.enable_rc6=0 did not help (suggested here
https://www.qubes-os.org/doc/thinkpad-troubleshooting/#thinkpads-with-intel-hd-3
000-graphics)
* intel_pstate=disable did not help (suggested here:
http://www.thinkwiki.org/wiki/Installing_Fedora_24_on_a_ThinkPad_X1_Yoga#Success
_Chart_-_Out_of_the_box_experience)
### UEFI boot
UEFI mode is not usable as Grub refuses to boot any menu option for some
reason for every version of Qubes OS I have tested. I disabled secure boot.
The following error message is shown:
/EndEntire
file path: /<device_path>/File/(\EFI\BOOT)/File(xen.efi)/EndEntire
Xen 4.6.1 (c/s) EFI loader
Failed to boot both default and fallback entries.
I already tried the things mentioned here:
https://www.qubes-os.org/doc/uefi-troubleshooting/
as suggested in
https://groups.google.com/d/msg/qubes-users/vPDD4rgNXx4/5faeFS-RBgAJ
This does not help.
### Kernel update
4.1.24 works with graphics problems
4.4.31 does not boot (platform resets when kernel is loaded, no kernel
messages) following
https://groups.google.com/forum/#!msg/qubes-users/m8sWoyV58_E/HYdReRIYBAAJ
4.8.11-100.vanilla.knurd.fc23 boots but hangs after the root filesystem has
been mounted (FDE pw entered). A _ keeps appearing for like .5 seconds all 4
seconds.
4.8.12-12 Works without issues.
`qubes-dom0-update --enablerepo=qubes-dom0-unstable kernel` and `dnf upgrade
kernel` worked!
### Screen brightness
By default the screen brightness can not be controlled by xfce and is at
maximum. There is a workaround for this:
dom0# qubes-dom0-update bc inotify-tools
And then run
https://github.com/rickybrent/x1yoga-scripts/blob/master/x1yoga-backlight-mon.sh
in dom0.
To start the script automatically at boot you can use "Sessions and Startup"
from xfce or other means.
### Touch screen
Works without issues in the default configuration. See sys-usb for more details.
### AEM
I only got AEM working without owner nor SRK password set. As soon as I set
any one of the passwords (even after full TPM clear), the password is being
asked for at boot. But the password is not accepted (error: "Key not found in
persistent storage"). When setting both passwords to well known, then it works
with the exception that the secret message is not shown in plymouth but only
on the text console (switched with ESC).
I removed the plymouth packages from dracut again with `dnf remove
'*plymouth*' && dracut -f` which solved it.
I expect that this problem was caused by the in place upgrade from R3.1 to
R3.2 or the fact that I removed the plymouth packages previously for debugging
and later reinstalled them on R3.2.
TXT seems to not work. If enabled in the UEFI setup, the platform resets after
grub. The last message shown is that 6th_gen_i5_i7_SINIT_71.BIN has been
loaded. I updated the AEM config in /etc to use SRTM for now.
I will retry with a clean install when possible but for now it works with the
mentioned limitations.
### Grub
Grub is horribly slow in default config on this machine. You can read the few
text lines as they start appearing on the screen and are only able to make
selections when it is done.
Set `GRUB_TERMINAL=console` in `/etc/default/grub` and regen grub.cfg to
workaround this.
### sys-usb
Required the `qvm-prefs sys-usb -s pci_strictreset false` workaround [1]
unfortunately. I was not able to fix this by any UEFI setting.
[1]:
https://www.qubes-os.org/doc/user-faq/#i-created-a-usbvm-and-assigned-usb-contro
llers-to-it-now-the-usbvm-wont-boot
I tried USB mouse usage which works but this does not make the touch screen
work again. I did not yet check touch screen + sys-usb in more detail yet,
maybe later.
### Network
Ethernet works out of the box with Fedora 23 and Debian 8 and 9. Had no issue
after resuming from S3.
WLAN works after installing firmware-iwlwifi in Debian 9. The only problem is
that almost all times after resuming from S3, the net VM needs to be restarted
to get wlan working again. The following is logged in sys-net:
[14543.999216] e1000e: eth0 NIC Link is Down
[14548.117695] e1000e: eth0 NIC Link is Down
[14548.314301] IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
[23785.273315] e1000e: eth0 NIC Link is Down
[23785.307940] wlan0: deauthenticating from xx:xx:xx:xx:xx:xx by local choice
(Reason: 3=DEAUTH_LEAVING)
[23786.152843] Freezing user space processes ... (elapsed 0.001 seconds) done.
[23786.154342] Freezing remaining freezable tasks ... (elapsed 0.000 seconds)
done.
[23786.155692] PM: freeze of devices complete after 0.347 msecs
[23786.155697] suspending xenstore...
[23786.155764] PM: late freeze of devices complete after 0.065 msecs
[23786.171420] PM: noirq freeze of devices complete after 15.649 msecs
[23786.172443] xen:grant_table: Grant tables using version 1 layout
[23786.172443] PM: noirq thaw of devices complete after 0.708 msecs
[23786.172443] PM: early thaw of devices complete after 0.086 msecs
[23786.172846] PM: thaw of devices complete after 0.407 msecs
[23786.172846] Restarting tasks ... done.
[23809.722077] IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
[23810.002035] IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
[23810.006535] IPv6: ADDRCONF(NETDEV_UP): wlan0: link is not ready
[23810.008657] iwlwifi 0000:00:01.0: L1 Enabled - LTR Enabled
[23810.010616] iwlwifi 0000:00:01.0: L1 Enabled - LTR Enabled
[23815.012114] iwlwifi 0000:00:01.0: Failed to load firmware chunk!
[23815.012150] iwlwifi 0000:00:01.0: Could not load the [0] uCode section
[23815.012182] iwlwifi 0000:00:01.0: Failed to start INIT ucode: -110
[23815.012208] iwlwifi 0000:00:01.0: Failed to run INIT ucode: -110
[23815.042145] iwlwifi 0000:00:01.0: L1 Enabled - LTR Enabled
[23815.044004] iwlwifi 0000:00:01.0: L1 Enabled - LTR Enabled
[23820.043139] iwlwifi 0000:00:01.0: Failed to load firmware chunk!
[23820.043194] iwlwifi 0000:00:01.0: Could not load the [0] uCode section
[23820.043230] iwlwifi 0000:00:01.0: Failed to start INIT ucode: -110
[23820.043249] iwlwifi 0000:00:01.0: Failed to run INIT ucode: -110
[23820.049489] iwlwifi 0000:00:01.0: L1 Enabled - LTR Enabled
[23820.051445] iwlwifi 0000:00:01.0: L1 Enabled - LTR Enabled
[23825.054064] iwlwifi 0000:00:01.0: Failed to load firmware chunk!
[23825.054078] iwlwifi 0000:00:01.0: Could not load the [0] uCode section
[23825.054088] iwlwifi 0000:00:01.0: Failed to start INIT ucode: -110
[23825.054093] iwlwifi 0000:00:01.0: Failed to run INIT ucode: -110
[23835.017335] iwlwifi 0000:00:01.0: L1 Enabled - LTR Enabled
[23835.019072] iwlwifi 0000:00:01.0: L1 Enabled - LTR Enabled
### UEFI Firmware versions
Most of the testing was done using the N1FET44W (1.18) version which the laptop
shipped with. I am now using the latest N1FET47W (N1FUR14W, 1.21) version
without issues. SHA512 sums:
66482797a45526a3b3e44ea67731d586b505933413dd884fc42df4825890f29cf228aa0f18a0d28c
490de1854937a3ed6cb5a2a53929f7cb4245002ea8ba5e8c
n1fur14w.img
06bc63be4a846e9336281877300c2e4d75c8a8bd7bb9487cff8bc7c7d2f08fb0559558cc29a660c2
e3c580da3e5844d1e2382cd39936448d0da81246f7ded9b8
n1fur14w.iso
### Other issues
* At least in CSM, the machine seems to be unable to boot from microSD.
* Powering up after suspend/S3 does/did not always work. The problem is
sometimes that pressing the power button when the system is in suspend does
not have any effect. The system has to be turned of by long pressing the power
button and then normally booted. Not yet sure what causes it. Might be related
to AC power connected.
* Hibernate S4 does not work: hibernate.target: Job hibernate.target/start
failed with result 'dependency'.
* TrackPoint scrolling, the usual X11 workaround works just fine.
### Works out of the box
* Webcam after attaching it via qvm-usb to a VM
* Speakers, headset jack
### HCL
Pull request already opened:
https://github.com/QubesOS/qubes-hcl/pull/4
I will update it with a link to this post on the ML.
- --
Live long and prosper
Robin `ypid` Schneider --
https://me.ypid.de/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQIcBAEBCAAGBQJYe+hWAAoJEIb9mAu/GkD4f8EQAKRl1uoTXPXgeNDH2q8DeO0J
cCTmHB4LyTKa1qvE8qR/Ojwo9qXH7SkKSDWlHZuEnBqOzEeN8y+71SQSx92Ov2KD
3oh8fJm22hlE4iwDdVKu0r+Aj1fcPMMsCMWYQBfEsi+w37Mkqc8wyZSfjnU6IDPp
4mzh+CLDm63R8a2+J0RgrJCo9z6ifJPES5p3tc8MBIYATQuoy0EVDCALQPC+Y1nF
dqaQizm4BZepq4WcB24pGVCYcaQYsi2YL1Gi0lmnDq7YQrLxckL8XKJW4VsRRC2C
0o6C5uqvKXBh2xAEkDzgiekL/AdPD8sbd8kPktBwm6Gglj8uRMlz2+P2nFwVHFmT
RfvradL/oY7RTMifa/PjHXPRyVNcz/1Kok4bEHUB8+AY15tyfCA3z2hXG0nD0YcM
AK/NtjMpanzjPOORnRwU6CjGfOoa6RekX6xWOnzK5cwNuZH5zEMVuZR0JPp/tWLC
NJ3rvrMya9K2L6IRlBtg5MEZweIDAKIRw9BXGkynNRrT8KpX1/S+waeV6NCgEMVX
S+2rTpdQekeWGrdQsFL0ub/3BNT4cmkUXBF2kgM++KWeGUQuw2I3koqfGhlwixTD
a7R/vlM7j/Xao5wKPSglZe0ss8sXfd8kOGpoSJZdtsvMHlthVfxLYaaQFTlR+UCt
W++2B+peAej3BTDjbQ2f
=nQzc
-----END PGP SIGNATURE-----