Update Qubes 3.2 man pages

Requested by : QubesOS/qubes-issues#3538
Related to   : QubesOS/qubes-issues#3495
This commit is contained in:
Andrew David Wong 2018-02-11 19:15:10 -06:00
parent 723671501a
commit 7a1ef06898
No known key found for this signature in database
GPG Key ID: 8CE137352A019A17
33 changed files with 1103 additions and 853 deletions

View File

@ -13,17 +13,20 @@ Dom0 Command-Line Tools for Qubes 3.2
===================================== =====================================
* [qubes-dom0-update](/doc/tools/3.2/dom0/qubes-dom0-update/) * [qubes-dom0-update](/doc/tools/3.2/dom0/qubes-dom0-update/)
* [qubes-guid](/doc/tools/3.2/dom0/qubes_guid/)
* [qubes-prefs](/doc/tools/3.2/dom0/qubes-prefs/) * [qubes-prefs](/doc/tools/3.2/dom0/qubes-prefs/)
* [qvm-add-appvm](/doc/tools/3.2/dom0/qvm-add-appvm/) * [qvm-add-appvm](/doc/tools/3.2/dom0/qvm-add-appvm/)
* [qvm-add-template](/doc/tools/3.2/dom0/qvm-add-template/) * [qvm-add-template](/doc/tools/3.2/dom0/qvm-add-template/)
* [qvm-backup-restore](/doc/tools/3.2/dom0/qvm-backup-restore/) * [qvm-backup-restore](/doc/tools/3.2/dom0/qvm-backup-restore/)
* [qvm-backup](/doc/tools/3.2/dom0/qvm-backup/) * [qvm-backup](/doc/tools/3.2/dom0/qvm-backup/)
* [qvm-block](/doc/tools/3.2/dom0/qvm-block/) * [qvm-block](/doc/tools/3.2/dom0/qvm-block/)
* [qvm-check](/doc/tools/3.2/dom0/qvm-check/)
* [qvm-clone](/doc/tools/3.2/dom0/qvm-clone/) * [qvm-clone](/doc/tools/3.2/dom0/qvm-clone/)
* [qvm-create-default-dvm](/doc/tools/3.2/dom0/qvm-create-default-dvm/) * [qvm-create-default-dvm](/doc/tools/3.2/dom0/qvm-create-default-dvm/)
* [qvm-create](/doc/tools/3.2/dom0/qvm-create/) * [qvm-create](/doc/tools/3.2/dom0/qvm-create/)
* [qvm-firewall](/doc/tools/3.2/dom0/qvm-firewall/) * [qvm-firewall](/doc/tools/3.2/dom0/qvm-firewall/)
* [qvm-grow-private](/doc/tools/3.2/dom0/qvm-grow-private/) * [qvm-grow-private](/doc/tools/3.2/dom0/qvm-grow-private/)
* [qvm-grow-root](/doc/tools/3.2/dom0/qvm-grow-root/)
* [qvm-ls](/doc/tools/3.2/dom0/qvm-ls/) * [qvm-ls](/doc/tools/3.2/dom0/qvm-ls/)
* [qvm-kill](/doc/tools/3.2/dom0/qvm-kill/) * [qvm-kill](/doc/tools/3.2/dom0/qvm-kill/)
* [qvm-pci](/doc/tools/3.2/dom0/qvm-pci/) * [qvm-pci](/doc/tools/3.2/dom0/qvm-pci/)
@ -36,4 +39,5 @@ Dom0 Command-Line Tools for Qubes 3.2
* [qvm-start](/doc/tools/3.2/dom0/qvm-start/) * [qvm-start](/doc/tools/3.2/dom0/qvm-start/)
* [qvm-sync-appmenus](/doc/tools/3.2/dom0/qvm-sync-appmenus/) * [qvm-sync-appmenus](/doc/tools/3.2/dom0/qvm-sync-appmenus/)
* [qvm-template-commit](/doc/tools/3.2/dom0/qvm-template-commit/) * [qvm-template-commit](/doc/tools/3.2/dom0/qvm-template-commit/)
* [qvm-usb](/doc/tools/3.2/dom0/qvm-usb/)

View File

@ -9,32 +9,29 @@ redirect_from:
- /wiki/Dom0Tools/QubesPrefs/ - /wiki/Dom0Tools/QubesPrefs/
--- ---
```
===========
qubes-prefs qubes-prefs
=========== ===========
NAME NAME
---- ====
qubes-prefs - display system-wide Qubes settings, such as: qubes-prefs - display system-wide Qubes settings, such as:
- clock VM - clock VM
- update VM - update VM
- default template - default template
- default firewallVM - default firewallVM
- default kernel - default kernel
- default netVM - default netVM
Date
2012-04-13
SYNOPSIS SYNOPSIS
-------- ========
| qubes-prefs
qubes-prefs
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -0,0 +1,41 @@
---
layout: doc
title: qubes_guid
permalink: /doc/tools/3.2/dom0/qubes_guid/
redirect_from:
- /doc/dom0-tools/qubes_guid/
- /en/doc/dom0-tools/qubes_guid/
---
```
==========
qubes_guid
==========
NAME
====
qubes_guid
SYNOPSIS
========
| qubes_guid -d domain_id [-c color] [-l label_index] [-i icon name, no suffix] [-v] [-q]
OPTIONS
=======
-v
Increase log verbosity
-q
Decrease log verbosity
Log levels:
0. only errors
1. some basic messages (default)
2. debug
AUTHORS
=======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
| Rafal Wojtczuk <rafal at invisiblethingslab dot com>
| Marek Marczykowski <marmarek at invisiblethingslab dot com>
```

View File

@ -9,39 +9,35 @@ redirect_from:
- /wiki/Dom0Tools/QvmAddAppvm/ - /wiki/Dom0Tools/QvmAddAppvm/
--- ---
```
=============
qvm-add-appvm qvm-add-appvm
============= =============
NAME NAME
---- ====
qvm-add-appvm - add an already installed appvm to the Qubes DB qvm-add-appvm - add an already installed appvm to the Qubes DB
WARNING: Normally you should not need this command, and you should use qvm-create instead! WARNING: Normally you should not need this command, and you should use qvm-create instead!
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-add-appvm [options] <appvm-name> <vm-template-name>
qvm-add-appvm [options] \<appvm-name\> \<vm-template-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -p DIR_PATH, --path=DIR_PATH
Specify path to the template directory
-p DIR\_PATH, --path=DIR\_PATH -c CONF_FILE, --conf=CONF_FILE
Specify path to the template directory Specify the Xen VM .conf file to use(relative to the template dir path)
--force-root
-c CONF\_FILE, --conf=CONF\_FILE Force to run, even with root privileges
Specify the Xen VM .conf file to use(relative to the template dir path)
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,40 +9,33 @@ redirect_from:
- /wiki/Dom0Tools/QvmAddTemplate/ - /wiki/Dom0Tools/QvmAddTemplate/
--- ---
```
================
qvm-add-template qvm-add-template
================ ================
NAME NAME
---- ====
qvm-add-template - adds an already installed template to the Qubes DB qvm-add-template - adds an already installed template to the Qubes DB
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-add-template [options] <vm-template-name>
qvm-add-template [options] \<vm-template-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -p DIR_PATH, --path=DIR_PATH
Specify path to the template directory
-p DIR\_PATH, --path=DIR\_PATH -c CONF_FILE, --conf=CONF_FILE
Specify path to the template directory Specify the Xen VM .conf file to use(relative to the template dir path)
--rpm
-c CONF\_FILE, --conf=CONF\_FILE Template files have been installed by RPM
Specify the Xen VM .conf file to use(relative to the template dir path)
--rpm
Template files have been installed by RPM
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,70 +9,66 @@ redirect_from:
- /wiki/Dom0Tools/QvmBackupRestore/ - /wiki/Dom0Tools/QvmBackupRestore/
--- ---
```
==================
qvm-backup-restore qvm-backup-restore
================== ==================
NAME NAME
---- ====
qvm-backup-restore - restores Qubes VMs from backup qvm-backup-restore - restores Qubes VMs from backup
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-backup-restore [options] <backup-dir>
qvm-backup-restore [options] \<backup-dir\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit --verify-only
Do not restore the data, only verify backup integrity
--verify-only --skip-broken
Do not restore the data, only verify backup integrity Do not restore VMs that have missing templates or netvms
--ignore-missing
--skip-broken Ignore missing templates and netvms, and restore the VMs anyway
Do not restore VMs that have missing templates or netvms --skip-conflicting
Do not restore VMs that are already present on the host
--ignore-missing --force-root
Ignore missing templates and netvms, and restore the VMs anyway Force to run with root privileges
--replace-template=REPLACE_TEMPLATE
--skip-conflicting Restore VMs using another template, syntax: old-template-name:new-template-name (can be repeated)
Do not restore VMs that are already present on the host -x EXCLUDE, --exclude=EXCLUDE
Skip restore of specified VM (can be repeated)
--force-root --skip-dom0-home
Force to run with root privileges Do not restore dom0's user home directory
--ignore-username-mismatch
--replace-template=REPLACE\_TEMPLATE Ignore dom0 username mismatch when restoring dom0's user home directory
Restore VMs using another template, syntax: old-template-name:new-template-name (can be repeated) -d APPVM, --dest-vm=APPVM
Restore from a backup located in a specific AppVM
-x EXCLUDE, --exclude=EXCLUDE -e, --encrypted
Skip restore of specified VM (can be repeated) The backup is encrypted
-p, --passphrase-file
--skip-dom0-home Read passphrase from file, or use '-' to read from stdin
Do not restore dom0's user home directory -z, --compressed
The backup is compressed
--ignore-username-mismatch --paranoid-mode, --plan-b
Ignore dom0 username mismatch when restoring dom0's user home directory Treat the backup as untrusted, disable restoring things potentially
compromising security of dom0/other VMs, even when such data is properly
-d APPVM, --dest-vm=APPVM authenticated. This may be used to restore a backup made on compromissed
Restore from a backup located in a specific AppVM system. Things currently affected by this option:
- disable dom0 home restore
-e, --encrypted - reject compressed backups
The backup is encrypted - reject old backup formats (Qubes R2 and older)
- more strict validation of VM names (for example don't allow '..' in it)
-z, --compressed - do not restore firewall rules, attached PCI devices, attached block
The backup is compressed devices, menu entries
--debug
--debug Enable (a lot of) debug output
Enable (a lot of) debug output
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,34 +9,51 @@ redirect_from:
- /wiki/Dom0Tools/QvmBackup/ - /wiki/Dom0Tools/QvmBackup/
--- ---
```
==========
qvm-backup qvm-backup
========== ==========
NAME NAME
---- ====
qvm-backup qvm-backup
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-backup [options] <backup-dir-path> [vms-to-be-included ...]
qvm-backup [options] \<backup-dir-path\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -x EXCLUDE_LIST, --exclude=EXCLUDE_LIST
Exclude the specified VM from backup (might be repeated)
-x EXCLUDE\_LIST, --exclude=EXCLUDE\_LIST --force-root
Exclude the specified VM from backup (might be repeated) Force to run with root privileges
-d, --dest-vm
Specify the destination VM to which the backup will be set (implies -e)
-e, --encrypt
Encrypt the backup
--no-encrypt
Skip encryption even if sending the backup to a VM
-p, --passphrase-file
Read passphrase from a file, or use '-' to read from stdin
-E, --enc-algo
Specify a non-default encryption algorithm. For a list of supported algorithms, execute 'openssl list-cipher-algorithms' (implies -e)
-H, --hmac-algo
Specify a non-default HMAC algorithm. For a list of supported algorithms, execute 'openssl list-message-digest-algorithms'
-z, --compress
Compress the backup
-Z, --compress-filter
Specify a non-default compression filter program (default: gzip)
--tmpdir
Specify a temporary directory (if you have at least 1GB free RAM in dom0, use of /tmp is advised) (default: /var/tmp)
--debug
Enable (a lot of) debug output
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -10,52 +10,49 @@ redirect_from:
- /wiki/Dom0Tools/QvmBlock/ - /wiki/Dom0Tools/QvmBlock/
--- ---
```
=========
qvm-block qvm-block
========= =========
NAME NAME
---- ====
qvm-block - list/set VM PCI devices. qvm-block - list/set VM PCI devices.
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-block -l [options]
qvm-block -l [options] | qvm-block -a [options] <vm-name> <device-vm-name>:<device>
qvm-block -a [options] \<device\> \<vm-name\> | qvm-block -A [options] <vm-name> <file-vm-name>:<file>
qvm-block -d [options] \<device\> | qvm-block -d [options] <device-vm-name>:<device>
qvm-block -d [options] \<vm-name\> | qvm-block -d [options] <vm-name>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -l, --list
List block devices
-l, --list -A, --attach-file
List block devices Attach specified file instead of physical device
-a, --attach
-a, --attach Attach block device to specified VM
Attach block device to specified VM -d, --detach
Detach block device
-d, --detach -f FRONTEND, --frontend=FRONTEND
Detach block device Specify device name at destination VM [default: xvdi]
--ro
-f FRONTEND, --frontend=FRONTEND Force read-only mode
Specify device name at destination VM [default: xvdi] --no-auto-detach
Fail when device already connected to other VM
--ro --show-system-disks
Force read-only mode List also system disks
--force-root
--no-auto-detach Force to run, even with root privileges
Fail when device already connected to other VM
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -0,0 +1,41 @@
---
layout: doc
title: qvm-check
permalink: /doc/tools/3.2/dom0/qvm-check/
redirect_from:
- /doc/dom0-tools/qvm-check/
- /en/doc/dom0-tools/qvm-check/
---
```
=========
qvm-check
=========
NAME
====
qvm-check - Specify no state options to check if VM exists
SYNOPSIS
========
| qvm-check [options] <vm-name>
OPTIONS
=======
-h, --help
Show this help message and exit
-q, --quiet
Be quiet
--running
Determine if VM is running
--paused
Determine if VM is paused
--template
Determine if VM is a template
AUTHORS
=======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
| Rafal Wojtczuk <rafal at invisiblethingslab dot com>
| Marek Marczykowski <marmarek at invisiblethingslab dot com>
```

View File

@ -9,37 +9,36 @@ redirect_from:
- /wiki/Dom0Tools/QvmClone/ - /wiki/Dom0Tools/QvmClone/
--- ---
```
=========
qvm-clone qvm-clone
========= =========
NAME NAME
---- ====
qvm-clone - clones an existing VM by copying all its disk files qvm-clone - clones an existing VM by copying all its disk files
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-clone [options] <src-name> <new-name>
qvm-clone [options] \<src-name\> \<new-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -q, --quiet
Be quiet
-q, --quiet -p DIR_PATH, --path=DIR_PATH
Be quiet Specify path to the template directory
--force-root
-p DIR\_PATH, --path=DIR\_PATH Force to run, even with root privileges
Specify path to the template directory -P, --pool
Specify in to which storage pool to clone
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
| Rafal Wojtczuk <rafal at invisiblethingslab dot com>
| Marek Marczykowski <marmarek at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> ```
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\>

View File

@ -9,40 +9,40 @@ redirect_from:
- /wiki/Dom0Tools/QvmCreateDefaultDvm/ - /wiki/Dom0Tools/QvmCreateDefaultDvm/
--- ---
```
======================
qvm-create-default-dvm qvm-create-default-dvm
====================== ======================
NAME NAME
---- ====
qvm-create-default-dvm - creates a default disposable VM qvm-create-default-dvm - creates a default disposable VM
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-create-default-dvm templatename|--default-template|--used-template [script-name|--default-script]
qvm-create-default-dvm templatename|--default-template|--used-template [script-name|--default-script]
OPTIONS OPTIONS
------- =======
templatename
Base DispVM on given template. The command will create AppVM named after
template with "-dvm" suffix. This VM will be used to create DispVM
savefile. If you want to customize DispVM, use this VM - take a look at
https://wiki.qubes-os.org/wiki/UserDoc/DispVMCustomization
templatename --default-template
Base DispVM on given template. The command will create AppVM named after template with "-dvm" suffix. This VM will be used to create DispVM savefile. If you want to customize DispVM, use this VM - take a look at <https://wiki.qubes-os.org/wiki/UserDoc/DispVMCustomization> Use default template for the DispVM
--default-template --used-template
Use default template for the DispVM Use the same template as earlier
--used-template --default-script
Use the same template as earlier Use default script for seeding DispVM home.
--default-script
Use default script for seeding DispVM home.
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,73 +9,58 @@ redirect_from:
- /wiki/Dom0Tools/QvmCreate/ - /wiki/Dom0Tools/QvmCreate/
--- ---
```
==========
qvm-create qvm-create
========== ==========
NAME NAME
---- ====
qvm-create - creates a new VM qvm-create - creates a new VM
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-create [options] <vm-name>
qvm-create [options] \<vm-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -t TEMPLATE, --template=TEMPLATE
Specify the TemplateVM to use
-t TEMPLATE, --template=TEMPLATE -l LABEL, --label=LABEL
Specify the TemplateVM to use Specify the label to use for the new VM (e.g. red, yellow, green, ...)
-p, --proxy
-l LABEL, --label=LABEL Create ProxyVM
Specify the label to use for the new VM (e.g. red, yellow, green, ...) -n, --net
Create NetVM
-p, --proxy -H, --hvm
Create ProxyVM Create HVM (standalone, unless --template option used)
--hvm-template
-n, --net Create HVM template
Create NetVM -R ROOT_MOVE, --root-move-from=ROOT_MOVE
Use provided root.img instead of default/empty one
-H, --hvm (file will be MOVED)
Create HVM (standalone, unless --template option used) -r ROOT_COPY, --root-copy-from=ROOT_COPY
Use provided root.img instead of default/empty one
--hvm-template (file will be COPIED)
Create HVM template -s, --standalone
Create standalone VM - independent of template
-R ROOT\_MOVE, --root-move-from=ROOT\_MOVE -m MEM, --mem=MEM
Use provided root.img instead of default/empty one (file will be MOVED) Initial memory size (in MB)
-c VCPUS, --vcpus=VCPUS
-r ROOT\_COPY, --root-copy-from=ROOT\_COPY VCPUs count
Use provided root.img instead of default/empty one (file will be COPIED) -i, --internal
Create VM for internal use only (hidden in qubes-manager, no appmenus)
-s, --standalone --force-root
Create standalone VM - independent of template Force to run, even with root privileges
-q, --quiet
-m MEM, --mem=MEM Be quiet
Initial memory size (in MB)
-c VCPUS, --vcpus=VCPUS
VCPUs count
-i, --internal
Create VM for internal use only (hidden in qubes-manager, no appmenus)
--force-root
Force to run, even with root privileges
-q, --quiet
Be quiet
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
| Rafal Wojtczuk <rafal at invisiblethingslab dot com>
| Marek Marczykowski <marmarek at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> ```
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\>

View File

@ -9,60 +9,53 @@ redirect_from:
- /wiki/Dom0Tools/QvmFirewall/ - /wiki/Dom0Tools/QvmFirewall/
--- ---
```
============
qvm-firewall qvm-firewall
============ ============
NAME NAME
---- ====
qvm-firewall - manage VM's firewall rules
qvm-firewall
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-firewall [-n] <vm-name> [action] [rule spec]
qvm-firewall [-n] \<vm-name\> [action] [rule spec] Rule specification can be one of:
1. address|hostname[/netmask] tcp|udp port[-port]
Rule specification can be one of: 2. address|hostname[/netmask] tcp|udp service_name
1. address|hostname[/netmask] tcp|udp port[-port] 3. address|hostname[/netmask] any
2. address|hostname[/netmask] tcp|udp service\_name
3. address|hostname[/netmask] any
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -l, --list
List firewall settings (default action)
-l, --list -a, --add
List firewall settings (default action) Add rule
-d, --del
-a, --add Remove rule (given by number or by rule spec)
Add rule -P SET_POLICY, --policy=SET_POLICY
Set firewall policy (allow/deny)
-d, --del -i SET_ICMP, --icmp=SET_ICMP
Remove rule (given by number or by rule spec) Set ICMP access (allow/deny)
-D SET_DNS, --dns=SET_DNS
-P SET\_POLICY, --policy=SET\_POLICY Set DNS access (allow/deny)
Set firewall policy (allow/deny) -Y SET_YUM_PROXY, --yum-proxy=SET_YUM_PROXY
Set access to Qubes yum proxy (allow/deny).
-i SET\_ICMP, --icmp=SET\_ICMP *Note:* if set to "deny", access will be rejected even if policy set to "allow"
Set ICMP access (allow/deny) -r, --reload
Reload firewall (implied by any change action)
-D SET\_DNS, --dns=SET\_DNS -n, --numeric
Set DNS access (allow/deny) Display port numbers instead of services (makes sense only with --list)
--force-root
-Y SET\_YUM\_PROXY, --yum-proxy=SET\_YUM\_PROXY Force to run, even with root privileges
Set access to Qubes yum proxy (allow/deny). *Note:* if set to "deny", access will be rejected even if policy set to "allow"
-n, --numeric
Display port numbers instead of services (makes sense only with --list)
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,31 +9,27 @@ redirect_from:
- /wiki/Dom0Tools/QvmGrowPrivate/ - /wiki/Dom0Tools/QvmGrowPrivate/
--- ---
```
================
qvm-grow-private qvm-grow-private
================ ================
NAME NAME
---- ====
qvm-grow-private - increase private storage capacity of a specified VM qvm-grow-private - increase private storage capacity of a specified VM
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-grow-private <vm-name> <size>
qvm-grow-private \<vm-name\> \<size\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -0,0 +1,35 @@
---
layout: doc
title: qvm-grow-root
permalink: /doc/tools/3.2/dom0/qvm-grow-root/
redirect_from:
- /doc/dom0-tools/qvm-grow-root/
- /en/doc/dom0-tools/qvm-grow-root/
---
```
=============
qvm-grow-root
=============
NAME
====
qvm-grow-root - increase root storage capacity of a specified VM
SYNOPSIS
========
| qvm-grow-root <vm-name> <size>
OPTIONS
=======
-h, --help
Show this help message and exit
--allow-start
Allow VM to be started to complete the operation
AUTHORS
=======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
| Rafal Wojtczuk <rafal at invisiblethingslab dot com>
| Marek Marczykowski <marmarek at invisiblethingslab dot com>
```

View File

@ -9,31 +9,28 @@ redirect_from:
- /wiki/Dom0Tools/QvmKill/ - /wiki/Dom0Tools/QvmKill/
--- ---
```
========
qvm-kill qvm-kill
======== ========
NAME NAME
---- ====
qvm-kill - kills the specified VM qvm-kill - kills the specified VM
Date
2012-04-10
SYNOPSIS SYNOPSIS
-------- ========
| qvm-kill [options] <vm-name>
qvm-kill [options] \<vm-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,55 +9,47 @@ redirect_from:
- /wiki/Dom0Tools/QvmLs/ - /wiki/Dom0Tools/QvmLs/
--- ---
```
======
qvm-ls qvm-ls
====== ======
NAME NAME
---- ====
qvm-ls - list VMs and various information about their state qvm-ls - list VMs and various information about their state
Date
2012-04-03
SYNOPSIS SYNOPSIS
-------- ========
| qvm-ls [options] <vm-name>
qvm-ls [options] \<vm-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show help message and exit
Show help message and exit -n, --network
Show network addresses assigned to VMs
-n, --network -c, --cpu
Show network addresses assigned to VMs Show CPU load
-m, --mem
-c, --cpu Show memory usage
Show CPU load -d, --disk
Show VM disk utilization statistics
-m, --mem -i, --ids
Show memory usage Show Qubes and Xen id
-k, --kernel
-d, --disk Show VM kernel options
Show VM disk utilization statistics -b, --last-backup
Show date of last VM backup
-i, --ids --raw-list
Show Qubes and Xen id List only VM names one per line
--raw-data
-k, --kernel Display specify data of specified VMs. Intended for bash-parsing.
Show VM kernel options --list-fields
List field names valid for --raw-data
-b, --last-backup
Show date of last VM backup
--raw-list
List only VM names one per line
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,46 +9,41 @@ redirect_from:
- /wiki/Dom0Tools/QvmPci/ - /wiki/Dom0Tools/QvmPci/
--- ---
```
=======
qvm-pci qvm-pci
======= =======
NAME NAME
---- ====
qvm-pci - list/set VM PCI devices qvm-pci - list/set VM PCI devices
Date
2012-04-11
SYNOPSIS SYNOPSIS
-------- ========
| qvm-pci -l [options] <vm-name>
qvm-pci -l [options] \<vm-name\> | qvm-pci -a [options] <vm-name> <device>
qvm-pci -a [options] \<vm-name\> \<device\> | qvm-pci -d [options] <vm-name> <device>
qvm-pci -d [options] \<vm-name\> \<device\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -l, --list
List VM PCI devices
-l, --list -a, --add
List VM PCI devices Add a PCI device to specified VM
-C, --add-class
-a, --add Add all devices of given class:
Add a PCI device to specified VM net - network interfaces,
usb - USB controllers
-C, --add-class -d, --delete
Add all devices of given class: Remove a PCI device from specified VM
net - network interfaces, usb - USB controllers --offline-mode
Offline mode
-d, --delete
Remove a PCI device from specified VM
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,150 +9,220 @@ redirect_from:
- /wiki/Dom0Tools/QvmPrefs/ - /wiki/Dom0Tools/QvmPrefs/
--- ---
```
=========
qvm-prefs qvm-prefs
========= =========
NAME NAME
---- ====
qvm-prefs - list/set various per-VM properties qvm-prefs - list/set various per-VM properties
Date
2012-04-11
SYNOPSIS SYNOPSIS
-------- ========
| qvm-prefs -l [options] <vm-name>
| qvm-prefs -g [options] <vm-name> <property>
| qvm-prefs -s [options] <vm-name> <property> [...]
qvm-prefs -l [options] \<vm-name\>
qvm-prefs -g [options] \<vm-name\> \<property\>
qvm-prefs -s [options] \<vm-name\> \<property\> [...]
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -l, --list
List properties of a specified VM
-l, --list -g, --get
List properties of a specified VM Get a single property of a specified VM
-s, --set
-g, --get Set properties of a specified VM
Get a single property of a specified VM --force-root
Force to run, even with root privileges
-s, --set --offline-mode
Set properties of a specified VM Offline mode
PROPERTIES PROPERTIES
---------- ==========
include\_in\_backups include_in_backups
Accepted values: `True`, `False` Accepted values: ``True``, ``False``
Control whenever this VM will be included in backups by default (for now works only in qubes-manager). You can always manually select or deselect any VM for backup. Control whenever this VM will be included in backups by default (for now
works only in qubes-manager). You can always manually select or
deselect any VM for backup.
pcidevs pcidevs
PCI devices assigned to the VM. Should be edited using qvm-pci tool. PCI devices assigned to the VM. Should be edited using qvm-pci tool.
pci\_strictreset pci_strictreset
Accepted values: `True`, `False` Accepted values: ``True``, ``False``
Control whether prevent assigning to VM a device which does not support any reset method. Generally such devices should not be assigned to any VM, because there will be no way to reset device state after VM shutdown, so the device could attack next VM to which it will be assigned. But in some cases it could make sense - for example when the VM to which it is assigned is trusted one, or is running all the time. Control whether prevent assigning to VM a device which does not support any
reset method. Generally such devices should not be assigned to any VM,
because there will be no way to reset device state after VM shutdown, so
the device could attack next VM to which it will be assigned. But in some
cases it could make sense - for example when the VM to which it is assigned
is trusted one, or is running all the time.
label pci_e820_host
Accepted values: `red`, `orange`, `yellow`, `green`, `gray`, `blue`, `purple`, `black` Accepted values: ``True``, ``False``
Color of VM label (icon, appmenus, windows border). If VM is running, change will be applied at first VM restart. Give VM with PCI devices a memory map (e820) of the host. This is
required for some devices to properly resolve conflicts in address space.
This option is enabled by default for VMs with PCI devices and have no
effect for VMs without devices.
netvm label
Accepted values: netvm name, `default`, `none` Accepted values: ``red``, ``orange``, ``yellow``, ``green``, ``gray``,
``blue``, ``purple``, ``black``
To which NetVM connect. Setting to `default` will follow system-global default NetVM (managed by qubes-prefs). Setting to `none` will disable networking in this VM. Color of VM label (icon, appmenus, windows border). If VM is running,
change will be applied at first VM restart.
dispvm\_netvm netvm
Accepted values: netvm name, `default`, `none` Accepted values: netvm name, ``default``, ``none``
Which NetVM should be used for Disposable VMs started by this one. `default` is to use the same NetVM as the VM itself. To which NetVM connect. Setting to ``default`` will follow system-global
default NetVM (managed by qubes-prefs). Setting to ``none`` will disable
networking in this VM.
maxmem dispvm_netvm
Accepted values: memory size in MB Accepted values: netvm name, ``default``, ``none``
Maximum memory size available for this VM. Dynamic memory management (aka qmemman) will not be able to balloon over this limit. For VMs with qmemman disabled, this will be overridden by *memory* property (at VM startup). Which NetVM should be used for Disposable VMs started by this one.
``default`` is to use the same NetVM as the VM itself.
memory maxmem
Accepted values: memory size in MB Accepted values: memory size in MB
Initial memory size for VM. This should be large enough to allow VM startup - before qmemman starts managing memory for this VM. For VM with qmemman disabled, this is static memory size. Maximum memory size available for this VM. Dynamic memory management (aka
qmemman) will not be able to balloon over this limit. For VMs with
qmemman disabled, this will be overridden by *memory* property (at VM
startup).
kernel memory
Accepted values: kernel version, `default`, `none` Accepted values: memory size in MB
Kernel version to use (only for PV VMs). Available kernel versions will be listed when no value given (there are in /var/lib/qubes/vm-kernels). Setting to `default` will follow system-global default kernel (managed via qubes-prefs). Setting to `none` will use "kernels" subdir in VM directory - this allows having VM-specific kernel; also this the only case when /lib/modules is writable from within VM. Initial memory size for VM. This should be large enough to allow VM startup
- before qmemman starts managing memory for this VM. For VM with qmemman
disabled, this is static memory size.
template kernel
Accepted values: TemplateVM name Accepted values: kernel version, ``default``, ``none``
TemplateVM on which VM base. It can be changed only when VM isn't running. Kernel version to use (only for PV VMs). Available kernel versions will be
listed when no value given (there are in /var/lib/qubes/vm-kernels).
Setting to ``default`` will follow system-global default kernel (managed
via qubes-prefs). Setting to ``none`` will use "kernels" subdir in
VM directory - this allows having VM-specific kernel; also this the only
case when /lib/modules is writable from within VM.
vcpus template
Accepted values: no of CPUs Accepted values: TemplateVM name
Number of CPU (cores) available to VM. Some VM types (eg DispVM) will not work properly with more than one CPU. TemplateVM on which VM base. It can be changed only when VM isn't running.
kernelopts vcpus
Accepted values: string, `default` Accepted values: no of CPUs
VM kernel parameters (available only for PV VMs). This can be used to workaround some hardware specific problems (eg for NetVM). Setting to `default` will use some reasonable defaults (currently different for VMs with PCI devices and without). For VM without PCI devices `default` option means inherit this value from the VM template (if any). Some helpful options (for debugging purposes): `earlyprintk=xen`, `init=/bin/bash` Number of CPU (cores) available to VM. Some VM types (eg DispVM) will not
work properly with more than one CPU.
name kernelopts
Accepted values: alphanumerical name Accepted values: string, ``default``
Name of the VM. Can be only changed when VM isn't running. VM kernel parameters (available only for PV VMs). This can be used to
workaround some hardware specific problems (eg for NetVM). Setting to
``default`` will use some reasonable defaults (currently different for VMs
with PCI devices and without). For VM without PCI devices
``default`` option means inherit this value from the VM template (if any).
Some helpful options (for debugging purposes): ``earlyprintk=xen``,
``init=/bin/bash``
drive name
Accepted values: [hd:|cdrom:][backend-vm:]path Accepted values: alphanumerical name
Additional drive for the VM (available only for HVMs). This can be used to attach installation image. `path` can be file or physical device (eg. /dev/sr0). The same syntax can be used in qvm-start --drive - to attach drive only temporarily. Name of the VM. Can be only changed when VM isn't running.
mac drive
Accepted values: MAC address, `auto` Accepted values: [hd:\|cdrom:][backend-vm:]path
Can be used to force specific of virtual ethernet card in the VM. Setting to `auto` will use automatic-generated MAC - based on VM id. Especially useful when licensing requires a static MAC address. For template-based HVM `auto` mode means to clone template MAC. Additional drive for the VM (available only for HVMs). This can be used to
attach installation image. ``path`` can be file or physical device (eg.
/dev/sr0). The same syntax can be used in qvm-start --drive - to
attach drive only temporarily.
default\_user mac
Accepted values: username Accepted values: MAC address, ``auto``
Default user used by qvm-run. Note that it make sense only on non-standard template, as the standard one always have "user" account. Can be used to force specific of virtual ethernet card in the VM. Setting
to ``auto`` will use automatic-generated MAC - based on VM id. Especially
useful when licensing requires a static MAC address.
For template-based HVM ``auto`` mode means to clone template MAC.
debug default_user
Accepted values: `on`, `off` Accepted values: username
Enables debug mode for VM. This can be used to turn on/off verbose logging in many Qubes components at once (gui virtualization, VM kernel, some other services). For template-based HVM, enabling debug mode also disables automatic reset root.img (actually volatile.img) before each VM startup, so changes made to root filesystem stays intact. To force reset root.img when debug mode enabled, either change something in the template (simple start+stop will do, even touch its root.img is enough), or remove VM's volatile.img (check the path with qvm-prefs). Default user used by qvm-run. Note that it make sense only on non-standard
template, as the standard one always have "user" account.
qrexec\_installed debug
Accepted values: `True`, `False` Accepted values: ``on``, ``off``
This HVM have qrexec agent installed. When VM have qrexec agent installed, one can use qvm-run to start VM process, VM will benefit from Qubes RPC services (like file copy, or inter-vm clipboard). This option will be automatically turned on during Qubes Windows Tools installation, but if you install qrexec agent in some other OS, you need to turn this option on manually. Enables debug mode for VM. This can be used to turn on/off verbose logging
in many Qubes components at once (gui virtualization, VM kernel, some other
services).
For template-based HVM, enabling debug mode also disables automatic reset
root.img (actually volatile.img) before each VM startup, so changes made to
root filesystem stays intact. To force reset root.img when debug mode
enabled, either change something in the template (simple start+stop will
do, even touch its root.img is enough), or remove VM's volatile.img
(check the path with qvm-prefs).
guiagent\_installed qrexec_installed
Accepted values: `True`, `False` Accepted values: ``True``, ``False``
This HVM have gui agent installed. This option disables full screen GUI virtualization and enables per-window seemless GUI mode. This option will be automatically turned on during Qubes Windows Tools installation, but if you install Qubes gui agent in some other OS, you need to turn this option on manually. You can turn this option off to troubleshoot some early HVM OS boot problems (enter safe mode etc), but the option will be automatically enabled at first VM normal startup (and will take effect from the next startup). This HVM have qrexec agent installed. When VM have qrexec agent installed,
one can use qvm-run to start VM process, VM will benefit from Qubes RPC
services (like file copy, or inter-vm clipboard). This option will be
automatically turned on during Qubes Windows Tools installation, but if you
install qrexec agent in some other OS, you need to turn this option on
manually.
*Notice:* when Windows GUI agent is installed in the VM, SVGA device (used to full screen video) is disabled, so even if you disable this option, you will not get functional full desktop access (on normal VM startup). Use some other means for that (VNC, RDP or so). guiagent_installed
Accepted values: ``True``, ``False``
autostart This HVM have gui agent installed. This option disables full screen GUI
Accepted values: `True`, `False` virtualization and enables per-window seemless GUI mode. This option will
be automatically turned on during Qubes Windows Tools installation, but if
you install Qubes gui agent in some other OS, you need to turn this option
on manually. You can turn this option off to troubleshoot some early HVM OS
boot problems (enter safe mode etc), but the option will be automatically
enabled at first VM normal startup (and will take effect from the next
startup).
Start the VM during system startup. The default netvm is autostarted regardless of this setting. *Notice:* when Windows GUI agent is installed in the VM, SVGA device (used
to full screen video) is disabled, so even if you disable this
option, you will not get functional full desktop access (on normal VM
startup). Use some other means for that (VNC, RDP or so).
timezone autostart
Accepted values: `localtime`, time offset in seconds Accepted values: ``True``, ``False``
Set emulated HVM clock timezone. Use `localtime` (the default) to use the same time as dom0 have. Note that HVM will get only clock value, not the timezone itself, so if you use `localtime` setting, OS inside of HVM should also be configured to treat hardware clock as local time (and have proper timezone set). Start the VM during system startup. The default netvm is autostarted
regardless of this setting.
timezone
Accepted values: ``localtime``, time offset in seconds
Set emulated HVM clock timezone. Use ``localtime`` (the default) to use the
same time as dom0 have. Note that HVM will get only clock value, not the
timezone itself, so if you use ``localtime`` setting, OS inside of HVM
should also be configured to treat hardware clock as local time (and have
proper timezone set).
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,40 +9,33 @@ redirect_from:
- /wiki/Dom0Tools/QvmRemove/ - /wiki/Dom0Tools/QvmRemove/
--- ---
```
==========
qvm-remove qvm-remove
========== ==========
NAME NAME
---- ====
qvm-remove - remove a VM qvm-remove - remove a VM
Date
2012-04-11
SYNOPSIS SYNOPSIS
-------- ========
| qvm-remove [options] <vm-name>
qvm-remove [options] \<vm-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -q, --quiet
Be quiet
-q, --quiet --just-db
Be quiet Remove only from qubes.xml; do not remove any files
--force-root
--just-db Force to run, even with root privileges
Remove only from the Qubes Xen DB, do not remove any files
--force-root
Force to run, even with root privileges
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,34 +9,29 @@ redirect_from:
- /wiki/Dom0Tools/QvmRevertTemplateChanges/ - /wiki/Dom0Tools/QvmRevertTemplateChanges/
--- ---
```
===========================
qvm-revert-template-changes qvm-revert-template-changes
=========================== ===========================
NAME NAME
---- ====
qvm-revert-template-changes qvm-revert-template-changes
Date
2012-04-11
SYNOPSIS SYNOPSIS
-------- ========
| qvm-revert-template-changes [options] <template-name>
qvm-revert-template-changes [options] \<template-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit --force
Do not prompt for confirmation
--force
Do not prompt for confirmation
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,70 +9,67 @@ redirect_from:
- /wiki/Dom0Tools/QvmRun/ - /wiki/Dom0Tools/QvmRun/
--- ---
```
=======
qvm-run qvm-run
======= =======
NAME NAME
---- ====
qvm-run - run a command on a specified VM qvm-run - run a command on a specified VM
Date
2012-04-11
SYNOPSIS SYNOPSIS
-------- ========
| qvm-run [options] [<vm-name>] [<cmd>]
qvm-run [options] [\<vm-name\>] [\<cmd\>]
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -q, --quiet
Be quiet
-q, --quiet -a, --auto
Be quiet Auto start the VM if not running
-u USER, --user=USER
-a, --auto Run command in a VM as a specified user
Auto start the VM if not running --tray
Use tray notifications instead of stdout
-u USER, --user=USER --all
Run command in a VM as a specified user Run command on all currently running VMs (or all paused, in case of --unpause)
--exclude=EXCLUDE_LIST
--tray When --all is used: exclude this VM name (might be repeated)
Use tray notifications instead of stdout --wait
Wait for the VM(s) to shutdown
--all --shutdown
Run command on all currently running VMs (or all paused, in the case of --unpause) (deprecated) Do 'xl shutdown' for the VM(s) (can be combined this with --all and --wait)
--pause
--exclude=EXCLUDE\_LIST Do 'xl pause' for the VM(s) (can be combined this with --all and --wait)
When --all is used: exclude this VM name (might be repeated) --unpause
Do 'xl unpause' for the VM(s) (can be combined this with --all and --wait)
--wait -p, --pass-io
Wait for the VM(s) to shutdown Pass stdin/stdout/stderr from remote program
--localcmd=LOCALCMD
--shutdown With --pass-io, pass stdin/stdout/stderr to the given program
(deprecated) Do 'xl shutdown' for the VM(s) (can be combined this with --all and --wait) --nogui
Run command without gui
--pause --filter-escape-chars
Do 'xl pause' for the VM(s) (can be combined this with --all and --wait) Filter terminal escape sequences (default if output is terminal)
--no-filter-escape-chars
--unpause Do not filter terminal escape sequences - overrides --filter-escape-chars, DANGEROUS when output is terminal
Do 'xl unpause' for the VM(s) (can be combined this with --all and --wait) --no-color-output
Disable marking VM output with red color
-p, --pass-io --no-color-stderr
Pass stdin/stdout/stderr from remote program Disable marking VM stderr with red color
--color-output
--localcmd=LOCALCMD Force marking VM output with given ANSI style (use 31 for red)
With --pass-io, pass stdin/stdout/stderr to the given program --color-stderr
Force marking VM stderr with given ANSI style (use 31 for red)
--force --force
Force operation, even if may damage other VMs (eg. shutdown of NetVM) Force operation, even if may damage other VMs (eg. shutdown of NetVM)
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,129 +9,138 @@ redirect_from:
- /wiki/Dom0Tools/QvmService/ - /wiki/Dom0Tools/QvmService/
--- ---
```
===========
qvm-service qvm-service
=========== ===========
NAME NAME
---- ====
qvm-service - manage (Qubes-specific) services started in VM qvm-service - manage (Qubes-specific) services started in VM
Date
2012-05-30
SYNOPSIS SYNOPSIS
-------- ========
| qvm-service [-l] <vmname>
qvm-service [-l] \<vmname\> | qvm-service [-e|-d|-D] <vmname> <service>
qvm-service [-e|-d|-D] \<vmname\> \<service\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -l, --list
List services (default action)
-l, --list -e, --enable
List services (default action) Enable service
-d, --disable
-e, --enable Disable service
Enable service -D, --default
Reset service to its default state (remove from the list). Default state
-d, --disable means "lets VM choose" and can depend on VM type (NetVM, AppVM etc).
Disable service
-D, --default
Reset service to its default state (remove from the list). Default state means "lets VM choose" and can depend on VM type (NetVM, AppVM etc).
SUPPORTED SERVICES SUPPORTED SERVICES
------------------ ==================
This list can be incomplete as VM can implement any additional service without knowledge of qubes-core code. This list can be incomplete as VM can implement any additional service without knowledge of qubes-core code.
meminfo-writer meminfo-writer
Default: enabled everywhere excluding NetVM Default: enabled everywhere excluding NetVM
This service reports VM memory usage to dom0, which effectively enables dynamic memory management for the VM. This service reports VM memory usage to dom0, which effectively enables dynamic memory management for the VM.
*Note:* this service is enforced to be set by dom0 code. If you try to remove it (reset to default state), will be recreated with the rule: enabled if VM have no PCI devices assigned, otherwise disabled. *Note:* this service is enforced to be set by dom0 code. If you try to
remove it (reset to default state), will be recreated with the rule: enabled
if VM have no PCI devices assigned, otherwise disabled.
qubes-dvm qubes-dvm
Default: disabled Default: disabled
Used internally when creating DispVM savefile. Used internally when creating DispVM savefile.
qubes-firewall qubes-firewall
Default: enabled only in ProxyVM Default: enabled only in ProxyVM
Dynamic firewall manager, based on settings in dom0 (qvm-firewall, firewall tab in qubes-manager). This service is not supported in netvms. Dynamic firewall manager, based on settings in dom0 (qvm-firewall, firewall tab in qubes-manager).
This service is not supported in netvms.
qubes-network
Default: enabled only in NetVM and ProxyVM
qubes-network Expose network for other VMs. This includes enabling network forwarding, MASQUERADE, DNS redirection and basic firewall.
Default: enabled only in NetVM and ProxyVM
Expose network for other VMs. This includes enabling network forwarding, MASQUERADE, DNS redirection and basic firewall. qubes-netwatcher
Default: enabled only in ProxyVM
qubes-netwatcher Monitor IP change notification from NetVM. When received, reload qubes-firewall service (to force DNS resolution).
Default: enabled only in ProxyVM This service makes sense only with qubes-firewall enabled.
Monitor IP change notification from NetVM. When received, reload qubes-firewall service (to force DNS resolution). This service makes sense only with qubes-firewall enabled. qubes-update-check
Default: enabled
qubes-update-check Notify dom0 about updates available for this VM. This is shown in qubes-manager as 'update-pending' flag.
Default: enabled
Notify dom0 about updates available for this VM. This is shown in qubes-manager as 'update-pending' flag. cups
Default: enabled only in AppVM
cups Enable CUPS service. The user can disable cups in VM which do not need printing to speed up booting.
Default: enabled only in AppVM
Enable CUPS service. The user can disable cups in VM which do not need printing to speed up booting. crond
Default: disabled
crond Enable CRON service.
Default: disabled
Enable CRON service. To have cron jobs persist across reboots, /var/spool/cron is bind-mounted from /rw/bind-dirs. To override this see [Bind-Dir Instructions](/doc/bind-dirs/) ) network-manager
Default: enabled in NetVM
network-manager Enable NetworkManager. Only VM with direct access to network device needs
Default: enabled in NetVM this service, but can be useful in ProxyVM to ease VPN setup.
Enable NetworkManager. Only VM with direct access to network device needs this service, but can be useful in ProxyVM to ease VPN setup. ntpd
Default: disabled
ntpd Enable NTPD service. By default Qubes calls ntpdate every 6 minutes in
Default: disabled selected VM (aka ClockVM), then propagate the result using qrexec calls.
Enabling ntpd *do not* disable this behaviour.
Enable NTPD service. By default Qubes calls ntpdate every 6 minutes in selected VM (aka ClockVM), then propagate the result using qrexec calls. Enabling ntpd *do not* disable this behaviour. qubes-yum-proxy
Deprecated name for qubes-updates-proxy.
qubes-yum-proxy qubes-updates-proxy
Deprecated name for qubes-updates-proxy. Default: enabled in NetVM
qubes-updates-proxy Provide proxy service, which allow access only to yum repos. Filtering is
Default: enabled in NetVM done based on URLs, so it shouldn't be used as leak control (pretty easy to
bypass), but is enough to prevent some erroneous user actions.
Provide proxy service, which allow access only to yum repos. Filtering is done based on URLs, so it shouldn't be used as leak control (pretty easy to bypass), but is enough to prevent some erroneous user actions. yum-proxy-setup
Deprecated name for updates-proxy-setup.
yum-proxy-setup updates-proxy-setup
Deprecated name for updates-proxy-setup. Default: enabled in AppVM (also in templates)
updates-proxy-setup Setup yum at startup to use qubes-yum-proxy service.
Default: enabled in AppVM (also in templates)
Setup yum at startup to use qubes-yum-proxy service. *Note:* this service is automatically enabled when you allow VM to access
yum proxy (in firewall settings) and disabled when you deny access to yum
proxy.
*Note:* this service is automatically enabled when you allow VM to access yum proxy (in firewall settings) and disabled when you deny access to yum proxy. disable-default-route
Default: disabled
disable-default-route Disables the default route for networking. Enabling this service
Default: disabled will prevent the creation of the default route, but the VM will
still be able to reach it's direct neighbors. The functionality
is implemented in /usr/lib/qubes/setup-ip.
Disables the default route for networking. Enabling this service will prevent the creation of the default route, but the VM will still be able to reach it's direct neighbors. The functionality is implemented in /usr/lib/qubes/setup-ip. disable-dns-server
Default: disabled
disable-dns-server Enabling this service will result in an empty /etc/resolv.conf.
Default: disabled The functionality is implemented in /usr/lib/qubes/setup-ip.
Enabling this service will result in an empty /etc/resolv.conf. The functionality is implemented in /usr/lib/qubes/setup-ip.
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,46 +9,39 @@ redirect_from:
- /wiki/Dom0Tools/QvmShutdown/ - /wiki/Dom0Tools/QvmShutdown/
--- ---
```
============
qvm-shutdown qvm-shutdown
============ ============
NAME NAME
---- ====
qvm-shutdown qvm-shutdown
Date
2012-04-11
SYNOPSIS SYNOPSIS
-------- ========
| qvm-shutdown [options] <vm-name> [vm-name ...]
qvm-shutdown [options] \<vm-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -q, --quiet
Be quiet
-q, --quiet --force
Be quiet Force operation, even if may damage other VMs (eg. shutdown of NetVM)
--wait
--force Wait for the VM(s) to shutdown
Force operation, even if may damage other VMs (eg. shutdown of NetVM) --wait-time
Timeout after which VM will be killed when --wait is used
--wait --all
Wait for the VM(s) to shutdown Shutdown all running VMs
--exclude=EXCLUDE_LIST
--all When --all is used: exclude this VM name (might be repeated)
Shutdown all running VMs
--exclude=EXCLUDE\_LIST
When --all is used: exclude this VM name (might be repeated)
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,46 +9,49 @@ redirect_from:
- /wiki/Dom0Tools/QvmStart/ - /wiki/Dom0Tools/QvmStart/
--- ---
```
=========
qvm-start qvm-start
========= =========
NAME NAME
---- ====
qvm-start - start a specified VM qvm-start - start a specified VM
Date
2012-04-11
SYNOPSIS SYNOPSIS
-------- ========
| qvm-start [options] <vm-name>
qvm-start [options] \<vm-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit -q, --quiet
Be quiet
-q, --quiet --tray
Be quiet Use tray notifications instead of stdout
--no-guid
--no-guid Do not start the GUId (ignored)
Do not start the GUId (ignored) --drive
Temporarily attach specified drive as CD/DVD or hard disk (can be specified with prefix 'hd' or 'cdrom:', default is cdrom)
--console --hddisk
Attach debugging console to the newly started VM Temporarily attach specified drive as hard disk
--cdrom
--dvm Temporarily attach specified drive as CD/DVD
Do actions necessary when preparing DVM image --install-windows-tools
Attach Windows tools CDROM to the VM
--custom-config=CUSTOM\_CONFIG --dvm
Use custom Xen config instead of Qubes-generated one Do actions necessary when preparing DVM image
--custom-config=CUSTOM_CONFIG
Use custom Xen config instead of Qubes-generated one
--skip-if-running
Do no fail if the VM is already running
--debug
Enable debug mode for this VM (until its shutdown)
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,31 +9,29 @@ redirect_from:
- /wiki/Dom0Tools/QvmTemplateCommit/ - /wiki/Dom0Tools/QvmTemplateCommit/
--- ---
```
===================
qvm-template-commit qvm-template-commit
=================== ===================
NAME NAME
---- ====
qvm-template-commit qvm-template-commit
Date
2012-04-11
SYNOPSIS SYNOPSIS
-------- ========
| qvm-template-commit [options] <vm-name>
qvm-template-commit [options] \<vm-name\>
OPTIONS OPTIONS
------- =======
-h, --help
-h, --help Show this help message and exit
Show this help message and exit --offline-mode
Offline mode
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -0,0 +1,45 @@
---
layout: doc
title: qvm-usb
permalink: /doc/tools/3.2/dom0/qvm-usb/
redirect_from:
- /doc/dom0-tools/qvm-usb/
- /en/doc/dom0-tools/qvm-usb/
---
```
=======
qvm-usb
=======
NAME
====
qvm-usb - List/set VM USB devices
SYNOPSIS
========
| qvm-usb -l [options]
| qvm-usb -a [options] <vm-name> <device-vm-name>:<device>
| qvm-usb -d [options] <device-vm-name>:<device>
OPTIONS
=======
-h, --help
Show this help message and exit
-l, -list
List devices
-a, --attach
Attach specified device to specified VM
-d, --detach
Detach specified device
--no-auto-detach
Fail when device already connected to other VM
--force-root
Force to run, even with root privileges
AUTHORS
=======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
| Rafal Wojtczuk <rafal at invisiblethingslab dot com>
| Marek Marczykowski <marmarek at invisiblethingslab dot com>
```

View File

@ -12,6 +12,7 @@ redirect_from:
DomU Command-Line Tools for Qubes 3.2 DomU Command-Line Tools for Qubes 3.2
===================================== =====================================
* [qrexec-client-vm](/doc/tools/3.2/domU/qrexec-client-vm/)
* [qvm-copy-to-vm](/doc/tools/3.2/domU/qvm-copy-to-vm/) * [qvm-copy-to-vm](/doc/tools/3.2/domU/qvm-copy-to-vm/)
* [qvm-open-in-dvm](/doc/tools/3.2/domU/qvm-open-in-dvm/) * [qvm-open-in-dvm](/doc/tools/3.2/domU/qvm-open-in-dvm/)
* [qvm-open-in-vm](/doc/tools/3.2/domU/qvm-open-in-vm/) * [qvm-open-in-vm](/doc/tools/3.2/domU/qvm-open-in-vm/)

View File

@ -0,0 +1,86 @@
---
layout: doc
title: qrexec-client-vm
permalink: /doc/tools/3.2/domU/qrexec-client-vm/
redirect_from:
- /doc/domU-tools/qrexec-client-vm/
- /en/doc/domU-tools/qrexec-client-vm/
---
```
================
qrexec-client-vm
================
NAME
====
qrexec-client-vm - call Qubes RPC service
SYNOPSIS
========
| qrexec-client-vm *target_vmname* *service* [*local_program* [*local program arguments*]]
DESCRIPTION
===========
Call Qubes RPC (aka qrexec) service to a different VM. The service call request
is sent to dom0, where Qubes RPC policy is evaluated and when it allows the
call, it is forwarded to appropriate target VM (which may be different than
requested, if policy says so). Local program (if given) is started only
when service call is allowed by the policy.
Remote service can communicate with the caller (``qrexec-client-vm``) using
stdin/stdout. When *local_program* is given, its stdin/stdout is connected to
service stdin/stdout (stderr is not redirected), otherwise - service
stdin/stdout is connected to those of ``qrexec-client-vm``.
OPTIONS
=======
*target_vmname*
Name of target VM to which service is requested. Qubes RPC policy may
ignore this value and redirect call somewhere else.
This argument, can contain VM name, or one of special values:
* ``$dispvm`` - new Disposable VM
This field is limited to 31 characters (alphanumeric, plus ``-_.$``).
*service*
Requested service. Besides service name, it can contain a service argument
after ``+`` character. For example ``some.service+argument``.
This field is limited to 63 characters (alphanumeric, plus ``-_.$+``).
*local_program*
Full path to local program to be connected with remote service. Optional.
*local program arguments*
Arguments to *local_program*. Optional.
EXIT STATUS
===========
If service call is allowed by dom0 and ``qrexec-client-vm`` is started without
*local_program* argument, it reports remote service exit code.
If service call is allowed by dom0 and ``qrexec-client-vm`` is started with
*local_program* argument, it reports the local program exit code. There is no
way to learn exit code of remote service in this case.
In both cases, if process (local or remote) was terminated by a signal, exit
status is 128+signal number.
If service call is denied by dom0, ``qrexec-client-vm`` exit with status 126.
AUTHORS
=======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
| Rafal Wojtczuk <rafal at invisiblethingslab dot com>
| Marek Marczykowski-Górecki <marmarek at invisiblethingslab dot com>
```

View File

@ -9,31 +9,27 @@ redirect_from:
- /wiki/VmTools/QvmCopyToVm/ - /wiki/VmTools/QvmCopyToVm/
--- ---
```
==============
qvm-copy-to-vm qvm-copy-to-vm
============== ==============
NAME NAME
---- ====
qvm-copy-to-vm - copy specified files to specified destination VM qvm-copy-to-vm - copy specified files to specified destination VM
Date
2012-05-30
SYNOPSIS SYNOPSIS
-------- ========
| qvm-copy-to-vm [--without-progress] dest_vmname file [file]+
qvm-copy-to-vm [--without-progress] dest\_vmname file [file]+
OPTIONS OPTIONS
------- =======
--without-progress
--without-progress Don't display progress info
Don't display progress info
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,28 +9,25 @@ redirect_from:
- /wiki/VmTools/QvmOpenInDvm/ - /wiki/VmTools/QvmOpenInDvm/
--- ---
```
===============
qvm-open-in-dvm qvm-open-in-dvm
=============== ===============
NAME NAME
---- ====
qvm-open-in-dvm - open a specified file in disposable VM qvm-open-in-dvm - open a specified file in disposable VM
Date
2012-05-30
SYNOPSIS SYNOPSIS
-------- ========
| qvm-open-in-dvm filename
qvm-open-in-dvm filename
OPTIONS OPTIONS
------- =======
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,28 +9,25 @@ redirect_from:
- /wiki/VmTools/QvmOpenInVm/ - /wiki/VmTools/QvmOpenInVm/
--- ---
```
==============
qvm-open-in-vm qvm-open-in-vm
============== ==============
NAME NAME
---- ====
qvm-open-in-vm - open a specified file in other VM qvm-open-in-vm - open a specified file in other VM
Date
2012-05-30
SYNOPSIS SYNOPSIS
-------- ========
| qvm-open-in-vm vmname filename
qvm-open-in-vm vmname filename
OPTIONS OPTIONS
------- =======
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```

View File

@ -9,31 +9,27 @@ redirect_from:
- /wiki/VmTools/QvmRun/ - /wiki/VmTools/QvmRun/
--- ---
```
=======
qvm-run qvm-run
======= =======
NAME NAME
---- ====
qvm-run - run a specified command in a specified VM qvm-run - run a specified command in a specified VM
Date
2012-05-30
SYNOPSIS SYNOPSIS
-------- ========
| qvm-run vmname command [aguments]
qvm-run vmname command [arguments]
OPTIONS OPTIONS
------- =======
--dispvm
--dispvm Pass this option instead of vmname to start new DisposableVM
Pass this option instead of vmname to start new DisposableVM
AUTHORS AUTHORS
------- =======
| Joanna Rutkowska <joanna at invisiblethingslab dot com>
Joanna Rutkowska \<joanna at invisiblethingslab dot com\> | Rafal Wojtczuk <rafal at invisiblethingslab dot com>
Rafal Wojtczuk \<rafal at invisiblethingslab dot com\> | Marek Marczykowski <marmarek at invisiblethingslab dot com>
Marek Marczykowski \<marmarek at invisiblethingslab dot com\> ```