@marcan Also, would it be possible to disable USB until the OS is running? That’s also something Qubes OS needs, as we isolate the USB stack in a VM for security. Outside of Qubes OS, it would allow USBGuard to be used.