Things are “starting” to get confusing
inheritance (on create) persistence (on poweroff)
TemplateVM n/a everything
TemplateBasedVM /etc/skel/ to /home/ /rw/ (includes /home/ and bind-dirs)
DispVM /home/ nothing
Conceptually, dispVM is now more flexible/convenient than before but potentially less anonymous since they are based on templateBasedVM and not templateVM - meaning there are more opportunities to configure them badly.
Potential tickets:
- tb-updater needs to copy new TBB to
/etc/skel/
instead of/home/user
- set updateVM to
sys-whonix-dispVM
;
or better but less usable: create new disposable-serviceVM to handle updates & non-random clockVM; attach to netVM:sys-whonix
; disable update proxy insys-whonix
sys-whonix can reach non-torified Qubes updates proxy · Issue #3201 · QubesOS/qubes-issues · GitHub