The release of the Qubes operating system 4.2.2 is available, implementing the idea of using a hypervisor for strict isolation of applications and OS components (each class of applications and system services operate in separate virtual machines). It is recommended to have a system with 16 GB of RAM (minimum — 6 GB) and a 64-bit Intel or AMD CPU supporting VT-x with EPT/AMD-v with RVI and VT-d/AMD IOMMU technologies. Ideally, an Intel GPU is recommended (NVIDIA and AMD GPUs are not tested thoroughly enough). The size of the installation image is 6 GB (x86_64).
Applications in Qubes are divided into classes depending on the importance of the processed data and the tasks being solved. Each class of applications (for example, work, entertainment, banking operations), as well as system services (network subsystem, firewall, storage management, USB stack, etc.), run separately. virtual machines, launched using the Xen hypervisor. These applications are available within a single desktop and are visually highlighted with different colors for the window borders. Each environment has read access to the base root filesystem and local storage, which does not intersect with the storage of other environments, and a special service is used to facilitate the interaction of applications.
Fedora and Debian package bases can serve as the foundation for forming virtual environments; the community also supports templates for Ubuntu, Gentoo, and Arch Linux. Access to applications in a Windows virtual machine can also be arranged, along with the creation of virtual machines based on Whonix to provide anonymous access through Tor. The user interface is built on Xfce. When a user launches an application from the menu, that application starts in a specific virtual machine. The content of the virtual environments is determined by a set of templates.
The new release notes the update of program versions forming the base system environment (dom0). A template has been prepared for creating virtual environments based on Fedora 40.
In the 4.2 branch, to protect against attacks related to manipulating unicode characters and incorrect character codes in file names, restrictions regarding the use of extended characters in file names have been introduced. This change led to issues with copying and moving files containing non-Latin letters in their names. In version 4.2.2, the old behavior when handling file names has been restored by default, and a parameter 'allow-all-names' has been added to the qubes.Filecopy service for configuration.
Source: opennet.ru
