qubes-issues icon indicating copy to clipboard operation
qubes-issues copied to clipboard

DNF configuration hardening doesn’t appear to be persistent

Open DemiMarie opened this issue 5 months ago • 3 comments

Qubes OS release

Qubes OS 4.2

Brief summary

My understanding (from previous discussions) is that the GUI updater is expected to set deltarpm=0 and zchunk=0, but it either doesn’t set them or doesn’t set them persistently.

Steps to reproduce

  1. Install updates via the GUI.
  2. Check the contents of /etc/dnf/dnf.conf.

Expected behavior

zchunk=0 and deltarpm=0 or equivalent are present.

Actual behavior

zchunk=0 and deltarpm=0 or equivalent are not present.

Additional information

No response

DemiMarie avatar Jun 06 '25 22:06 DemiMarie

On distributions using DNF5 (which is all non-EOL Fedora versions) it's in /etc/dnf/libdnf5.conf.d/10-qubes.conf.

marmarek avatar Jun 06 '25 22:06 marmarek

On distributions using DNF5 (which is all non-EOL Fedora versions) it's in /etc/dnf/libdnf5.conf.d/10-qubes.conf.

My Fedora 41 template (which has been upgraded using the GUI updater) has an empty /etc/dnf/libdnf5.conf.d.

DemiMarie avatar Jun 08 '25 00:06 DemiMarie

Looks like missing backport.

marmarek avatar Jun 08 '25 00:06 marmarek

Automated announcement from builder-github

The package core-agent-linux has been pushed to the r4.2 testing repository for the Debian template. To test this update, first enable the testing repository in /etc/apt/sources.list.d/qubes-*.list by uncommenting the line containing bookworm-testing (or appropriate equivalent for your template version), then use the standard update command:

sudo apt-get update && sudo apt-get dist-upgrade

Changes included in this update

qubesos-bot avatar Jul 29 '25 15:07 qubesos-bot

Automated announcement from builder-github

The component core-agent-linux (including package core-agent-linux) has been pushed to the r4.2 testing repository for the Fedora template. To test this update, please install it with the following command:

sudo dnf update --enablerepo=qubes-vm-r4.2-current-testing

Changes included in this update

qubesos-bot avatar Jul 29 '25 16:07 qubesos-bot

Automated announcement from builder-github

The package core-agent-linux has been pushed to the r4.2 testing repository for the Debian template. To test this update, first enable the testing repository in /etc/apt/sources.list.d/qubes-*.list by uncommenting the line containing trixie-testing (or appropriate equivalent for your template version), then use the standard update command:

sudo apt-get update && sudo apt-get dist-upgrade

Changes included in this update

qubesos-bot avatar Jul 29 '25 16:07 qubesos-bot

Automated announcement from builder-github

The component core-agent-linux (including package core-agent-linux) has been pushed to the r4.2 testing repository for the Fedora template. To test this update, please install it with the following command:

sudo dnf update --enablerepo=qubes-vm-r4.2-current-testing

Changes included in this update

qubesos-bot avatar Jul 29 '25 16:07 qubesos-bot

Automated announcement from builder-github

The package core-agent-linux has been pushed to the r4.2 stable repository for the Debian template. To install this update, please use the standard update command:

sudo apt-get update && sudo apt-get dist-upgrade

Changes included in this update

qubesos-bot avatar Aug 08 '25 01:08 qubesos-bot

Automated announcement from builder-github

The package core-agent-linux has been pushed to the r4.2 stable repository for the Debian template. To install this update, please use the standard update command:

sudo apt-get update && sudo apt-get dist-upgrade

Changes included in this update

qubesos-bot avatar Aug 08 '25 01:08 qubesos-bot

Automated announcement from builder-github

The component core-agent-linux (including package core-agent-linux) has been pushed to the r4.2 stable repository for the Fedora template. To install this update, please use the standard update command:

sudo dnf update

Changes included in this update

qubesos-bot avatar Aug 08 '25 01:08 qubesos-bot

Automated announcement from builder-github

The component core-agent-linux (including package core-agent-linux) has been pushed to the r4.2 stable repository for the Fedora template. To install this update, please use the standard update command:

sudo dnf update

Changes included in this update

qubesos-bot avatar Aug 08 '25 01:08 qubesos-bot