20 Mar 2018 decide whether 4.0-rc5 is the final 4.0

159 views
Skip to first unread message

mirek.woj...@gmail.com

unread,
Mar 21, 2018, 10:03:59 AM3/21/18
to qubes-devel
Hi guys,

How about this case? ;)

Best,

Marek Marczykowski-Górecki

unread,
Mar 22, 2018, 11:51:03 AM3/22/18
to mirek.woj...@gmail.com, qubes-devel
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Wed, Mar 21, 2018 at 06:47:15AM -0700, mirek.woj...@gmail.com wrote:
> Hi guys,
>
> How about this case? ;)

Looks like rc5 is stable enough :) Final release will be in the middle of
next week.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAlqsm/MACgkQ24/THMrX
1yy3gggAmRO6J07s/szETum/XMNPA329NNvuT1gO13PtKbkQrazsKZzmKk0nfn/n
kJXJVRCPi6i7qZy99sr54zuVnH9gai88gfxqHs5gUeyTN8LqPP5Lvne/peCvhJ8h
jPZrmJ0XUv9VQ072D6y4vBfFn6AypdWIax+TuEuEtz9H12Lm+VYDScYsuGDpY7Mf
nMZt6rQ/nSw+/I0SDIvgEQAk7r4ffbE8CKxlAQ6QBWMpivDXFLb8FcBECCNaMOMt
q3CJMdVX+1kaiI9PY+hLTWzAlcg9UVIq1srH6sw3+DIKFgrUabNF4p6A2GNCoAVp
Hu3v4qkjINhaFnBjx9dHF81rPdEv9A==
=JxJN
-----END PGP SIGNATURE-----

Mirosław Wojciechowski

unread,
Mar 22, 2018, 3:52:41 PM3/22/18
to Marek Marczykowski-Górecki, qubes-devel
Thank you Marek for your answer. That is excellent news.
I only hope that there will be no delay ;) I'm waiting so long :D

Unman

unread,
Mar 22, 2018, 6:59:57 PM3/22/18
to Marek Marczykowski-Górecki, mirek.woj...@gmail.com, qubes-devel
On Thu, Mar 22, 2018 at 04:50:56PM +0100, Marek Marczykowski-Górecki wrote:
> On Wed, Mar 21, 2018 at 06:47:15AM -0700, mirek.woj...@gmail.com wrote:
> > Hi guys,
> >
> > How about this case? ;)
>
> Looks like rc5 is stable enough :) Final release will be in the middle of
> next week.
>
> --
> Best Regards,
> Marek Marczykowski-Górecki
> Invisible Things Lab
> A: Because it messes up the order in which people normally read text.
> Q: Why is top-posting such a bad thing?

Is this what's in the current repo or does it include packages from
current-testing or security-testing?

Marek Marczykowski-Górecki

unread,
Mar 22, 2018, 7:07:12 PM3/22/18
to Unman, mirek.woj...@gmail.com, qubes-devel
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Thu, Mar 22, 2018 at 10:59:54PM +0000, Unman wrote:
> On Thu, Mar 22, 2018 at 04:50:56PM +0100, Marek Marczykowski-Górecki wrote:
> > On Wed, Mar 21, 2018 at 06:47:15AM -0700, mirek.woj...@gmail.com wrote:
> > > Hi guys,
> > >
> > > How about this case? ;)
> >
> > Looks like rc5 is stable enough :) Final release will be in the middle of
> > next week.
>
> Is this what's in the current repo or does it include packages from
> current-testing or security-testing?

Current repo. There are a few issues (fixed in current-testing already),
but we don't want to risk breaking something that is already working
(see [1] for example). Updates in current-testing will migrate into current
few days after final 4.0 release (probably nearest Monday).
Yes, this means that some of the mitigations for spectre variant 2 will
be available only as an update. But as explained in QSB, those types of
attacks are already largely mitigated by separation provided by Qubes
and HVM/PVH.

[1] https://github.com/QubesOS/qubes-issues/issues/3703#issuecomment-374931517

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAlqtAioACgkQ24/THMrX
1yxjgwf+MRT0zc7syAnrUH6hlE3LUmM0ZKVkrnJW1oxpjVRTLLzz76LggvE/xuz2
EgVANREfsVMwY6cFSG5y1WXXF36ye/mC38HY0yv9Us4KuV1xq8w97PBNn7qbzIJc
/iiip/Z1R378m9+ghLOQqmSAcsIxQ/eg8NipnbY/ageaExObF4+L8eZJuJ9itqGA
/ceIPV4pj/xAxhuW/h0O6Jm3wQl5gbs3bwPx22wIZYyZZYKo1Dw4kRiJVkmKTzob
fLJGeZ0vOKA2agWwBWx2fMDZmy9+4u+xD0na7Dnb1L017WWOatl/G/H3MK+AC1hY
bbsWasnp76XVn4t15W0wE8t8C7jecQ==
=Zn5z
-----END PGP SIGNATURE-----

Unman

unread,
Mar 22, 2018, 7:27:41 PM3/22/18
to Marek Marczykowski-Górecki, mirek.woj...@gmail.com, qubes-devel
On Fri, Mar 23, 2018 at 12:07:03AM +0100, Marek Marczykowski-Górecki wrote:
> On Thu, Mar 22, 2018 at 10:59:54PM +0000, Unman wrote:
> > On Thu, Mar 22, 2018 at 04:50:56PM +0100, Marek Marczykowski-Górecki wrote:
> > > On Wed, Mar 21, 2018 at 06:47:15AM -0700, mirek.woj...@gmail.com wrote:
> > > > Hi guys,
> > > >
> > > > How about this case? ;)
> > >
> > > Looks like rc5 is stable enough :) Final release will be in the middle of
> > > next week.
> >
> > Is this what's in the current repo or does it include packages from
> > current-testing or security-testing?
>
> Current repo. There are a few issues (fixed in current-testing already),
> but we don't want to risk breaking something that is already working
> (see [1] for example). Updates in current-testing will migrate into current
> few days after final 4.0 release (probably nearest Monday).
> Yes, this means that some of the mitigations for spectre variant 2 will
> be available only as an update. But as explained in QSB, those types of
> attacks are already largely mitigated by separation provided by Qubes
> and HVM/PVH.
>
> [1] https://github.com/QubesOS/qubes-issues/issues/3703#issuecomment-374931517
>

Thanks Marek.
Excellent work all round

Andrew David Wong

unread,
Mar 22, 2018, 8:18:17 PM3/22/18
to Marek Marczykowski-Górecki, qubes-devel
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 2018-03-22 18:07, Marek Marczykowski-Górecki wrote:
> On Thu, Mar 22, 2018 at 10:59:54PM +0000, Unman wrote:
>> On Thu, Mar 22, 2018 at 04:50:56PM +0100, Marek Marczykowski-Górecki wrote:
>>> On Wed, Mar 21, 2018 at 06:47:15AM -0700, mirek.woj...@gmail.com wrote:
>>>> Hi guys,
>>>>
>>>> How about this case? ;)
>>>
>>> Looks like rc5 is stable enough :) Final release will be in the middle of
>>> next week.
>
>> Is this what's in the current repo or does it include packages from
>> current-testing or security-testing?
>
> Current repo. There are a few issues (fixed in current-testing already),
> but we don't want to risk breaking something that is already working
> (see [1] for example). Updates in current-testing will migrate into current
> few days after final 4.0 release (probably nearest Monday).
> Yes, this means that some of the mitigations for spectre variant 2 will
> be available only as an update. But as explained in QSB, those types of
> attacks are already largely mitigated by separation provided by Qubes
> and HVM/PVH.
>
> [1] https://github.com/QubesOS/qubes-issues/issues/3703#issuecomment-374931517
>

Marek, did you mean security-testing instead of current-testing?
According to QSB #37 [2], the Spectre SP2 mitigations are in
security-testing, not current-testing.

[2] https://www.qubes-os.org/news/2018/03/15/qsb-37-update/

- --
Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlq0R7cACgkQ203TvDlQ
MDAluxAAiBpsxdQ+U+1u1VOwodITlcP4OlPAMeBbwFHprmui2EX9sdLtIQvkr4xt
njd+rs/HY8dh9ZYXHDcVVLq4lKIBzBg+vd0qsGb2k5LICn9r3rHfHTs4JmdCTkx0
94HXiJgcgDQZXpjaKpAVf8VkuJCYfKASXkWk0pWXTpABCA6TfEuS7zoNl0JfHvRa
QAn9cKOPn3S5kdaOSdZj/heQ+n8yk8w7/v0FT7blqmpjpYtl90W7976J+arShfUt
2Z1E4jnphXxuCJb+rIClan+zMLPHCxUhJZNH/WPIyif7b7dgv+EU7cc4i2OIJ1XB
h9YdQrPsEztJ/3cwIIUUC/msESc1Ygw1yoqo36mgpIOyZ6jvyruBzVCS1MPgjz2Q
hZiho64C5qVtmRZfzTL+aZMxmlQ20a7oaniDJeZmvz0TXMGtt8GpU9AoWmDF9lpE
AS/jD/V+lOOPNr4rGMMaeWrSE+0CJPPw9FRA1ntoGWs1t1STg0csWBQDJlaN4tGu
/ltT0yq7DmoqM7RNfaMgGYCPO+rfFd7wkG2EluZTjHnke/Az/Ro1d7HTaa4IQB7c
yyu7IojS9cpXc3r/O9xADbx3/xTyI+5SFhjQ8Jgb403l3lxKg0QCL02oz4FiYHrz
p7eJmUBC1AeZCyfH4qBvtnvxKYD+PcStkiu94ovQyt8ZTX/CGJA=
=gCcs
-----END PGP SIGNATURE-----


Marek Marczykowski-Górecki

unread,
Mar 22, 2018, 8:22:50 PM3/22/18
to Andrew David Wong, qubes-devel
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Thu, Mar 22, 2018 at 07:18:10PM -0500, Andrew David Wong wrote:
> On 2018-03-22 18:07, Marek Marczykowski-Górecki wrote:
> > On Thu, Mar 22, 2018 at 10:59:54PM +0000, Unman wrote:
> >> On Thu, Mar 22, 2018 at 04:50:56PM +0100, Marek Marczykowski-Górecki wrote:
> >>> On Wed, Mar 21, 2018 at 06:47:15AM -0700, mirek.woj...@gmail.com wrote:
> >>>> Hi guys,
> >>>>
> >>>> How about this case? ;)
> >>>
> >>> Looks like rc5 is stable enough :) Final release will be in the middle of
> >>> next week.
> >
> >> Is this what's in the current repo or does it include packages from
> >> current-testing or security-testing?
> >
> > Current repo. There are a few issues (fixed in current-testing already),
> > but we don't want to risk breaking something that is already working
> > (see [1] for example). Updates in current-testing will migrate into current
> > few days after final 4.0 release (probably nearest Monday).
> > Yes, this means that some of the mitigations for spectre variant 2 will
> > be available only as an update. But as explained in QSB, those types of
> > attacks are already largely mitigated by separation provided by Qubes
> > and HVM/PVH.
> >
> > [1] https://github.com/QubesOS/qubes-issues/issues/3703#issuecomment-374931517
> >
>
> Marek, did you mean security-testing instead of current-testing?
> According to QSB #37 [2], the Spectre SP2 mitigations are in
> security-testing, not current-testing.

Both.
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAlqtE+QACgkQ24/THMrX
1ywy+wf/bsx5TmvdHVP1NoJDPVmAgaLw+PWhMY9ZrjVwOgQrvmTCp3/Rg8NnQ/3o
QFRZzNUI3zP1ReRpVvpbOzGu8+M7PNbGZHQNd/Ps3YGgSrdVZXQ3x5KYexTqX1x+
nklu2nAeT6NWKM38ZXy6LHh/j/teXpgr33kRnSwmPkLEgdTXwr8/whi3P6t3ut6A
rQz2rv27mEkoMdhkiDgR2FUcDqyNlwi0TeETtYzUnrP0Fpj5+QQLiX+Wt1YPo6YA
ahEbiyOQj2tYHL+3RtCAPioMfGfQAEvafR3l/Kg+hYv7qp0qJdEx5iLca707UbDu
8mAAugtFpNVfkjj2C0RkqHUl8KICxA==
=ASD5
-----END PGP SIGNATURE-----
Reply all
Reply to author
Forward
0 new messages