Qubes 4.1.1 OS update using virtualization for application isolation

An update of the Qubes 4.1.1 operating system has been generated, which implements the idea of ​​using a hypervisor for strict isolation of applications and OS components (each class of applications and system services run in separate virtual machines). Requires a system with 6 GB of RAM and a 64-bit Intel or AMD CPU with support for VT-x c EPT / AMD-v c RVI and VT-d / AMD IOMMU technologies, an Intel GPU is desirable (NVIDIA and AMD GPUs are not well tested ). The size of the installation image is 5.5 GB.

Applications in Qubes are divided into classes depending on the importance of the data being processed and the tasks being solved. Each application class (e.g. work, entertainment, banking) as well as system services (network subsystem, firewall, storage, USB stack, etc.) run in separate virtual machines that run using the Xen hypervisor . At the same time, these applications are available within the same desktop and are distinguished for clarity by different colors of the window frame. Each environment has read access to the underlying root FS and local storage that does not overlap with the storages of other environments; a special service is used to organize application interaction.

The Fedora and Debian package base can be used as the basis for the formation of virtual environments, and templates for Ubuntu, Gentoo and Arch Linux are also supported by the community. It is possible to organize access to applications in a Windows virtual machine, as well as create Whonix-based virtual machines to provide anonymous access via Tor. The user shell is based on Xfce. When a user launches an application from the menu, that application starts in a specific virtual machine. The content of virtual environments is defined by a set of templates.

In the new release, only the update of the versions of the programs that form the basic system environment (dom0) is noted. A template for creating virtual environments based on Fedora 36 has been prepared. By default, the Linux 5.15 kernel is proposed. The Qubes 4 branch is scheduled to be demaintained on August 4.0, and users of the old branch are encouraged to switch to using Qubes 4.1.

Source: opennet.ru

Add a comment