Thank you to our partners, donors, contributors, and testers!
This release would not be possible without generous support from our
partners (https://www.qubes-os.org/partners/) and donors (https://www.qubes-os.org/donate/), as well as contributions (https://www.qubes-os.org/doc/contributing/) from our active
community members, especially bug reports (https://www.qubes-os.org/doc/issue-tracking/) from our testers (https://www.qubes-os.org/doc/testing/). We are
eternally grateful to our excellent community for making the Qubes OS
Project a great example of open-source collaboration.
Release notes
The following list is also available on the Qubes OS 4.1 release notes (www.qubes-os.org/doc/rel…se-notes)
page.
Optional qubes-remote-support package now available from repositories
(strictly opt-in, no package installed by default; no new ports or
network connections open by default; requires explicit connection
initiation by the user, then requires sharing a code word with the
remote party before a connection can be established; see
#6364 (github.com/QubesOS…ues/6364) for more
information)
Qubes firewall reworked to be more defensive (see
#5540 (github.com/QubesOS…ues/5540) for
details)
Xen upgraded to version 4.14
Dom0 operating system upgraded to Fedora 32
Default desktop environment upgraded to Xfce 4.14
Upgraded default template releases
Experimental support for GUI running outside of dom0 (hybrid mode GUI
domain without real GPU passthrough; see
#5662 (github.com/QubesOS…ues/5662) for
details)
Experimental support for audio server running outside of dom0 (“Audio
domain”)
sys-firewall and sys-usb are now disposables by default
UEFI boot now loads GRUB, which in turn loads Xen, making the boot
path similar to legacy boot and allowing the user to modify boot
parameters or choose an alternate boot menu entry
New qrexec policy format (see
#4370 (github.com/QubesOS…ues/4370) for
details)
qrexec protocol improvements (see
#4909 (github.com/QubesOS…ues/4909) for
details)
New qrexec-policy daemon
Simplified using in-qube kernels
Windows USB and audio support courtesy of
tabit-pro (https://github.com/tabit-pro) (see
#5802 (github.com/QubesOS…ues/5802) and
#2624 (github.com/QubesOS…ues/2624))
Clarified disposable-related terminology and properties
Default kernelopts can now be specified by a kernel package
Improved support for high-resolution displays
Improved notifications when a system drive runs out of free space
Support for different cursor shapes
“Paranoid mode” backup restore option now properly supported using
disposables
Users can now choose between Debian and Fedora in the installer
Certain files and applications are now opened in disposables, e.g.,
Thunderbird email attachments
New graphical interface for managing testing repository updates
New “Cute Qube” icon family (replaces padlock icons)
Disposable qube types now use the disposable icon
New Template Manager tool for installing, removing, and updating
templates (meanwhile, the tool previously known as the “Template
Manager,” which was for mass template switching, has been integrated
into the Qube Manager)
The “file” storage driver has been deprecated in Qubes 4.1 and will be
removed in Qubes 4.2
property-del event renamed to property-reset to avoid confusion
qrexec no longer supports non-executable files in /etc/qubes-rpc
qrexec components have been reorganized into the core-qrexec
repository
The qvm-pool argument parser has been rewritten and improved
Removed the need for the out-of-tree u2mfn kernel module
Qrexec services can now run as a socket server
Improved template distribution mechanism
Now possible to restart qrexec-agent
The term “VM” has largely been replaced by “qube”