Or if we are enabling backports, then simply omit setting this apt config in VBox builds to begin with while designating the stable kernel during the build process?
Enabling backports is inappropriate for a distribution.
Enabling backports alone does nothing. Still required APT pinning, which again is inappropriate for a distribution.
References:
If not using virtualizer specific kernel versions: Would have to download the package from Debian backports and upload to Whonix stable.
If using virtualizer specific kernel versions: Would require some packaging hack. Perhaps require to recompile the kernel.
If recompile on developer machine - perhaps for all architectures.
I don’t like the idea of virtualizer specific kernel versions. That’s adding a lot complexity. Hard to develop / test since involving different tests on different virtualizers.
It would also only be effective for a platform that I don’t maintain, KVM.
(Qubes is not yetQubes VM kernel by default.)