After two years of development, the release of the Qubes 4.3.0 operating system has been presented, implementing the idea of using a hypervisor for strict isolation of applications and OS components (each class of applications and system services runs in separate virtual machines). It is recommended to have a system with 16 GB of RAM (minimum — 6 GB) and a 64-bit Intel or AMD CPU with support for VT-x with EPT/AMD-v with RVI and VT-d or AMD IOMMU, ideally with an Intel GPU (NVIDIA and AMD GPUs are not thoroughly tested). The size of the installation image is 7.8 GB (x86_64).
Applications in Qubes are divided into classes based on the importance of the processed data and the tasks to be accomplished. Each application class (for example, work, entertainment, banking operations), along with system services (network subsystem, firewall, storage management, USB stack, etc.), operates in separate virtual machines, launched using the Xen hypervisor. These applications are accessible within a single desktop and are visually distinguished by different colored window borders. Each environment has read access to the underlying root filesystem and local storage, which does not overlap with the storage of other environments, with a special service facilitating interaction between applications.

Fedora and Debian package bases can serve as the foundation for forming virtual environments; the community also supports templates for Ubuntu, Gentoo, and Arch Linux. Access to applications in a Windows virtual machine can also be arranged, along with the creation of virtual machines based on Whonix to provide anonymous access through Tor. The user interface is built on Xfce. When a user launches an application from the menu, that application starts in a specific virtual machine. The content of the virtual environments is determined by a set of templates.

Key Changes:
- The base environment Dom0 has been updated to the Fedora 41 package base, and the template for virtual environments has been updated to Fedora 42.
- The template for forming virtual environments based on Debian has been updated to the Debian 13 branch, and the template based on Whonix has been updated to Whonix 18.
- The Xen hypervisor has been updated to version 4.19 (previously Xen 4.17 was used).
- Support for proactive loading of disposable isolated environments (dispvm — disposable vm) has been implemented, allowing elimination of the 7-20 seconds delay when launching frequently used applications in disposable environments.
- An improved toolkit QWT (Qubes Windows Tools) for running Windows virtual machines has been proposed. Support for Windows 10 and 11 has been implemented. Support for Windows 7 has been discontinued.

- A new Device API for configuring automatic attachment of plug-in devices to virtual machines, such as USB drives, external sound and network cards, input devices, web cameras, and Bluetooth devices, has been implemented. A graphical interface for device passthrough configuration has been added. virtual machines.

- A new set of icons has been employed in Qube Manager and other graphical utilities.

- The ability to attach arbitrary text notes to virtual machines has been added.

- Application icon display has been implemented in the virtual machine configurator.

- Application menu navigation has been improved using the keyboard.
- A centralized service, qubes.TrayNotification, has been added for displaying notifications from different virtual machines.
- An option to launch the terminal with root privileges via the Qubes Domains widget has been added.
- Support for advanced format (AF) for working with disks with 4-kilobyte sector sizes has been added.
- Experimental support for configuration management via Ansible has been added.
- Experimental support for Qubes Air technology has been added, implementing the qrexec protocol and allowing the launch of external virtual machines.
- The default screensaver has been changed from XScreenSaver to xfce4-screensaver.
- Support for plug-in sound cards and sound devices with Bluetooth interface has been improved.

Source: opennet.ru





