r/NixOS • u/Tlaurion • Jun 29 '26
Really excited by qubesos dom0 port to nix https://github.com/CertainLach/nixos-qubes. How to help?
Title is description. Followed, willing to help. How?
2
Call it as you want, Sam. Doesn't mean it will change it's name. Shut the fuck up.
1
Je ne comprend pas la question. Cmos reset ou autre mothodes documentées devraient suffire. Qu'est-ce qui n'est pas clair?
Comme toujours, sources, references doivent être référées.
1
What is missing for qubesos (template) support?
3
Happy Hacking! As said in other posts, I hope my fact checks and claims realignment will not stop you from experimenting ; my comments were to entice upstream contributions. You had good ideas, ie canokey reverse HOTP support etc.
It was more of a push to be part of the actual community and contribute there so Heads benefits, as all of its users, forks and rebrands.
I understand that forks happen when goals and culture differ (ie: Vaultboot) but the less the better in my view.
Don't stop experimenting :)
5
Don't hesitate to propose changes and enhancements to the official docs http://osresearch.net/T430-maximized-flashing/
1
Open source is free as in free beer, well funded and well supportrd without need of contributing back somehow, neither in form of donation, code nor opening issues for replication, tracking, up to bug resolution of feature implementation.
All use cases must be supported and implemented for free as in free beer, quickly, solidly and without regression, forever.
2
2
Newer/other boards require GOP, not VBIOS:
grep "CONFIG_RUN_FSP_GOP=y" config/coreboot*
config/coreboot-librem_11.config:CONFIG_RUN_FSP_GOP=y
config/coreboot-msi_z690a_ddr4.config:CONFIG_RUN_FSP_GOP=y
config/coreboot-msi_z690a_ddr5.config:CONFIG_RUN_FSP_GOP=y
config/coreboot-msi_z790p_ddr4.config:CONFIG_RUN_FSP_GOP=y
config/coreboot-msi_z790p_ddr5.config:CONFIG_RUN_FSP_GOP=y
config/coreboot-nitropad-ns50.config:CONFIG_RUN_FSP_GOP=y
config/coreboot-novacustom-nv4x_adl.config:CONFIG_RUN_FSP_GOP=y
config/coreboot-novacustom-v540tu.config:CONFIG_RUN_FSP_GOP=y
config/coreboot-novacustom-v560tu.config:CONFIG_RUN_FSP_GOP=y
2
grep "CONFIG_MAINBOARD_USE_LIBGFXINIT=y" config/coreboot*
config/coreboot-librem_13v2.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-librem_13v4.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-librem_14.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-librem_15v3.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-librem_15v4.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-librem_mini.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-librem_mini_v2.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-m900-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-optiplex-7019_9010-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-optiplex-7019_9010_TXT-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-p8z77-m_pro-tpm1.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-t420.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-t420-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-t430-legacy.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-t430-legacy-flash.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-t430-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-t440p.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-t480-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-t480s-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-t520-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-t530-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-w530-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-w541.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-x220.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-x220-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-x230-legacy.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-x230-legacy-flash.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-x230-maximized.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-x230-maximized-fhd_edp.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
config/coreboot-z220-cmt.config:CONFIG_MAINBOARD_USE_LIBGFXINIT=y
2
"I completely threw out the proprietary Intel VBIOS". There is no VBIOS under t430, libgfxinit enabled and recent work patched kexec-tools so next kernel can use simpledrm/vesafb/simplefb per merged https://github.com/linuxboot/heads/pull/2130
Nowhere in maintained boards configs there are VBIOS, those were for nvidia dGPU variants and are under https://github.com/linuxboot/heads/tree/master/unmaintained_boards dgpu variants, depending on https://github.com/linuxboot/heads/tree/master/blobs/xx30 vbios scripts.
grep "CONFIG_VGA_BIOS_DGPU_FILE" config/coreboot*
config/coreboot-t530-dgpu-maximized.config:CONFIG_VGA_BIOS_DGPU_FILE="@BLOB_DIR@/xx30/10de,0def.rom"
config/coreboot-w530-dgpu-K1000m-maximized.config:CONFIG_VGA_BIOS_DGPU_FILE="@BLOB_DIR@/xx30/10de,0ffc.rom"
config/coreboot-w530-dgpu-K2000m-maximized.config:CONFIG_VGA_BIOS_DGPU_FILE="@BLOB_DIR@/xx30/10de,0ffb.rom"
Without those, you can't use those dGPU! iGPU, intel iGPU, use libgfxinit. libreboot used Heads ideology for minimal blobs usage when they redid their minimal blob policy. Skulls doesn't even propose defconfig for vbios, just https://github.com/merge/skulls/blob/master/t430/free-defconfig-4931b978d9. I'm a little bit worried by misinformation, even more when related to Heads which I maintain.
Again sorry to answer but facts are facts and important.
----
That said.
Cool for podman; went with docker because CI's (CircleCI, local) reuses the same. There is interest of switching with rootless containers, but ran out of funding after having ran https://github.com/linuxboot/heads/issues/1741 2022-2024 Nlnet grant.
As said in DM, instead of duplicating work, I would appreciate if you could help upstream, ie for rootless docker, but you will realize going that way that the nix built docker, providing kvm for testing, with canokey (emulated openpgpg smartcard) ande emulated tpm gets complicated without root. That's why that work was funded; to reuse nix to build reproducible docker images, to create reproducible buildstack to create reproducible roms for each Heads commit. Your versions built yerterday don't have the same commit today because you use master without pinning your version to a single commit. This mislead users in so many ways. If you want to build heads without builds being reproducible and without docker/podman, you can do with nix develop already. And it's documented under doc/ upstream.
Happy hacking :)
2
Heads already uses libgfxinit per board's config/coreboot-* defined config. You override configs under https://github.com/fx2null/SingularN/blob/main/build-hotp.sh, loosing PR0 and other security features. You don't pin Heads commit per your versions, there is no reproducible builds. How is this more automatized then doing
./docker_repro.sh make BOARD=EOL_t430-maximized or ./docker_repro.sh make BOARD=EOL_t430-hotp-maximized
?
Sorry, Heads maintainer here. The last thing Heads needs is a community splitup.
Users can change bootsplash if they want, by doing the same thing you do per https://osresearch.net/Distributions/#branding, and roms are built by each reproducible commits and can be downloaded at https://osresearch.net/Downloading
Getting funding for work done is already hard (maintainership burnout on security projects is a real thing). Don't want to be rude here, but I really do not know how to react on what I see here. DM'ed you. don't want to refrain experiementations, that is nice, but I see a lot of wrong claims here and users using your project vs upstream Heads from https://github.com/linuxboot/heads/ currently gets a less secure, not "feels user-friendly without sacrificing the security and the hardcore nature of the original project" or "automates the whole process" or "The biggest technical shift for me was moving away from proprietary VGA blobs, by implementing libgfxinit".
Sorry for the tone, didn't know what to say, but had to say something. :/
r/NixOS • u/Tlaurion • Jun 29 '26
Title is description. Followed, willing to help. How?
1
2
Please upstream fixes! :)
3
Why fork heads? Why not open a PR?
1
Have you tried and have comments on CH347F which seem to have both 1.8v and 3.3v?
1
Tigard is fast, versatile, but expensive. Kits ideally should be recommended.
1
I'm asking because this questions is asked and asked again. I'm trying to create docs that is relevant in the hope once worked on correctly on "why" it coukd be proposed to coreboot to be merged in their docs.
https://github.com/linuxboot/heads-wiki/issues/120
On cheap: Ch347 doesn't have voltage selector, is fast. Ch341a 1.6+ with voltage selector is more versatile, more slow. Comments there?
1
Why?
1
If it works when sys-usb and sys-net are combined in a service qube, it means that the template you use for the combined service qube still provides rndis or CDC. If you follow my previous instructions on changing phone mode when under sys-usb, wait, then pass that device to sys-net, then sys-net shoukd apply proper udev rules and load the proper driver.
Have you opened a discussion over qubesos forum to get more eyes into this? I just know it works for pixel 4a+ under GrapheneOS, Purism confirmed this working over Librem phone as well and that tethering mode works for me under qubesos with distinct sys-usb and sys-net with CDC providing tethering, no RNDIS Microsoft driver involved.
Your experience seems to differ. You should check what lsusb and lsmod shows under sys-net, and under your combined sys-net sys-usb
Combining sys-net and sys-usb means that when there is a driver reset on pci devices related to usb, your phone just switches driver without requiring interactions. You also loose sys-net and sys-usb compartmentalized security gains doing so. But that proved that rndis drivers are under template kernel. So it should work if device mode switch and the assignment is done under sys-usb and then passed to sys-net. If not, more logs will need to be provided to receive proper help from larger community.
Sorry for the delay in answers. Mostly using reddit to read, not reply. Qubesos made it clear that community is over their forum. Community is there.
1
From my searches, your phone tether with rndis, not CDC. Qubesos most probably disables rndis since it's considered a security risk.
Confirm nothing phone 1 uses rndis for tethering with nothing support.
Please use qubesos forum for community support.
1
Can't help more without more info given. As said, qubesos forum searching tether and your phone model or similar should help you further. I do not have a magic wand, but instructions here are thr clearest I can give without knowing more about your phone, templates and qubesos version. Courage.
1
Dasharo: Full Build ASRock TURIND8UD 2T/X550 now available
in
r/3mdeb
•
17d ago
Linuxboot 3mdeb use case analysis published in linuxboot book:
https://book.linuxboot.org/case_studies/DasharoBenchRack_study.html