Skip to content

feat: add VZVmnetNetworkDeviceAttachment support (macOS 26.0) - #205

Draft
norio-nomura wants to merge 15 commits into
Code-Hex:mainfrom
norio-nomura:feat-add-vmnet-network-device-attachment
Draft

norio-nomura wants to merge 15 commits into
Code-Hex:mainfrom
norio-nomura:feat-add-vmnet-network-device-attachment

Conversation

@norio-nomura

@norio-nomura norio-nomura commented Nov 22, 2025 •

Copy link
Copy Markdown
Contributor

feat: add VZVmnetNetworkDeviceAttachment support (macOS 26.0)

VZVmnetNetworkDeviceAttachment is an API that creates vmnet devices on VMs added in macOS 26.

see: https://developer.apple.com/documentation/virtualization/vzvmnetnetworkdeviceattachment?language=objc

It does not require the com.apple.vm.networking entitlement nor root privileges.
HostMode and SharedMode are supported.
In order for multiple VMs to communicate with each other in SharedMode, they must be started in the same executable and the same VmnetNetwork must be passed to NewVmnetNetworkDeviceAttachment() to create an attachment.

This change adds:

  • vz.VmnetNetworkDeviceAttachment represents VZVmnetNetworkDeviceAttachment in Go

  • vmnet package to use vmnet APIs that added on macOS 26.0

    • Return represents vmnet_return_t as error
      • ErrSuccess, ErrFailure, ...
    • Mode represents operating_modes_t
      • HostMode, SharedMode
    • NetworkConfiguration represents vmnet_network_configuration_t
    • Network represents vmnet_network_ref
    • Interface represents interface_ref
    • *FileAdaptorForInterfaces support File Handle based network device APIs on QEMU, krunkit, and vz.NewFileHandleNetworkDeviceAttachment
  • xpc package that providing <xpc/xpc.h> APIs to support implementing Mach service server/client to sharing serializations of vmnet.Network and file descriptors of vmnet.*FileAdaptorForInterfaces

  • vz_test.TestVmnetSharedModeAllowsCommunicationBetweenMultipleVMs

  • vz_test.TestVmnetSharedModeWithConfiguringIPv4

  • vz_test.TestVmnetNetworkShareModeSharingOverXpc
    TestVmnetNetworkShareModeSharingOverXpc tests sharing vmnet.Network in SharedMode over XPC communication.
    This test registers test executable as an Mach service and launches it using launchctl.
    The launched Mach service provides vmnet.Network serialization to clients upon request, after booting
    a VM using the provided vmnet.Network to ensure the network is functional on the server side.
    The client boots VM using the provided vmnet.Network serialization.

Edit: on macOS 26.2, "the same executable" restriction seems to be relaxed.

  • VZVmnetNetworkDeviceAttachment seems to allow connecting to subnet created by a different executable.
  • vmnet_interface_start_with_network seems to allow connecting to subnet created by an executable at same path? (may changing CDHash not affect?)
  • I don't know how far the restrictions have been relaxed.

Which issue(s) this PR fixes:

Mentioned in #198 (comment)

@norio-nomura norio-nomura changed the title feat: add VmnetNetworkDeviceAttachment support (macOS 26.0) feat: add VZVmnetNetworkDeviceAttachment support (macOS 26.0) Nov 22, 2025
@norio-nomura
norio-nomura force-pushed the feat-add-vmnet-network-device-attachment branch 2 times, most recently from 6617c8f to 6a1f741 Compare November 22, 2025 12:34
norio-nomura added a commit to norio-nomura/lima that referenced this pull request Nov 22, 2025
Based on `VMNET_SHARED_MODE`, and `VMNET_HOST_MODE`
```yaml
networks:
- vzShared: true
- vzHost: true
```
But, to sharing network between multiple VMs, `VZVmnetNetworkDeviceAttachment` requires VMs are launched by same process.

It depends on Code-Hex/vz#205

Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
Comment thread vmnet.go Outdated
@nirs

nirs commented Nov 24, 2025

Copy link
Copy Markdown

This can be used by multiple processes like this:

  1. Start a network process create the vmnet_network_ref, starting a xpc listener
  2. Start vm process, obtaining the vmnet_network_ref from the xpc server
  3. Start more vms using same vmnet_network_ref...
  4. Wait until vms exit
  5. Terminate network process

@norio-nomura
norio-nomura force-pushed the feat-add-vmnet-network-device-attachment branch from 5a7a116 to 72cc1d4 Compare November 26, 2025 02:58
@norio-nomura

Copy link
Copy Markdown
Contributor Author

This can be used by multiple processes like this:

In this procedure, I confirmed that VMs launched from multiple processes can share networks with each other. 👍🏻
It seems that it can be reproduced in the unit test, so I will try to make a unit test.

@norio-nomura
norio-nomura force-pushed the feat-add-vmnet-network-device-attachment branch from 72cc1d4 to 9506cbd Compare December 2, 2025 03:56
@norio-nomura

Copy link
Copy Markdown
Contributor Author

It seems that it can be reproduced in the unit test, so I will try to make a unit test.

Added unit test and pkg/xpc.

@norio-nomura
norio-nomura marked this pull request as draft December 2, 2025 04:01
@norio-nomura

norio-nomura commented Dec 2, 2025 •

Copy link
Copy Markdown
Contributor Author

Added unit test and pkg/xpc.

I'll try this added xpc package with lima to make it work. Until then, it's a draft.

@norio-nomura
norio-nomura force-pushed the feat-add-vmnet-network-device-attachment branch 5 times, most recently from 7bf24c1 to 007c2a5 Compare December 3, 2025 07:26
norio-nomura added a commit to norio-nomura/lima that referenced this pull request Dec 3, 2025
Based on `VMNET_SHARED_MODE`, and `VMNET_HOST_MODE`
```yaml
networks:
- vzShared: true
- vzHost: true
```
But, to sharing network between multiple VMs, `VZVmnetNetworkDeviceAttachment` requires VMs are launched by same process.

It depends on Code-Hex/vz#205

Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
@norio-nomura
norio-nomura force-pushed the feat-add-vmnet-network-device-attachment branch 2 times, most recently from aba95bd to ba619f5 Compare December 4, 2025 03:51
@norio-nomura
norio-nomura force-pushed the feat-add-vmnet-network-device-attachment branch 2 times, most recently from d3fad75 to 7a58378 Compare December 15, 2025 03:39
norio-nomura added a commit to norio-nomura/lima that referenced this pull request Dec 15, 2025
Based on `VMNET_SHARED_MODE`, and `VMNET_HOST_MODE`
```yaml
networks:
- vzShared: true
- vzHost: true
```
But, to sharing network between multiple VMs, `VZVmnetNetworkDeviceAttachment` requires VMs are launched by same process.

It depends on Code-Hex/vz#205

Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
@norio-nomura
norio-nomura force-pushed the feat-add-vmnet-network-device-attachment branch from 7a58378 to 33858c0 Compare December 16, 2025 14:25

@nirs nirs left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I did not review most of this change, just the stange part of about marking bridged mode as depracated.

Comment thread pkg/xpc/xpc.m Outdated
Comment thread vmnet.go Outdated
Comment thread vmnet.go Outdated
@norio-nomura
norio-nomura force-pushed the feat-add-vmnet-network-device-attachment branch from f048f6e to 3b512d7 Compare December 17, 2025 00:10
norio-nomura added a commit to norio-nomura/lima that referenced this pull request Dec 17, 2025
Based on `VMNET_SHARED_MODE`, and `VMNET_HOST_MODE`
```yaml
networks:
- vzShared: true
- vzHost: true
```
But, to sharing network between multiple VMs, `VZVmnetNetworkDeviceAttachment` requires VMs are launched by same process.

It depends on Code-Hex/vz#205

Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
@norio-nomura
norio-nomura marked this pull request as ready for review December 17, 2025 05:20
To avoid crash when `Context` is canceled before receiving reply.

Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
@norio-nomura
norio-nomura force-pushed the feat-add-vmnet-network-device-attachment branch from 9241433 to ec911e3 Compare February 10, 2026 03:15
`vmnet`: Fix golangci-lint-v2 violations

`vmnet`: if iface.EnableVirtioHeader { packetSize += virtioNetHdrSize }

`vmnet`: Remove `object`

`vmnet`: Add doc comments to `*FileAdapterForInterface`s

`vmnet`: Refactor `*FileAdapterForInterface`s

- Remove written packet count from result of `WritePacketsTo*` in `PacketForwarder`
- Minimize differences between `pktDescsManager` and `msgHdrXArray`

`vmnet`: Handle `syscall.ENOBUFS` in `DatagramPacketForwarder.WritePacketsToConn`

`syscall.Sendmsg` may return `syscall.ENOBUFS` if there is not enough buffer set to the destination.

Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
- `StreamFileAdapterForInterface`:
  - Support partial read on `unix.Readv` in `readPacketsFromConn`

- `Datagram*FileAdapterForInterface`:
  - Add wait on `syscall.ENOBUFS` in `writePacketsToPacketConn`

Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
Use `*FileAdapterForInterface` APIs in `TestVmnetSharedModeAllowsCommunicationBetweenMultipleVMs`:
- `datagram.FileAdapterForInterface`
- `datagramx.FileAdapterForInterface`
Since they are compatible with `vz.NewFileHandleNetworkDeviceAttachment`.

Signed-off-by: Norio Nomura <norio.nomura@gmail.com>
@norio-nomura
norio-nomura force-pushed the feat-add-vmnet-network-device-attachment branch from ec911e3 to e27a5fb Compare February 10, 2026 03:30
norio-nomura added a commit to norio-nomura/lima that referenced this pull request Feb 10, 2026
Based on `VMNET_SHARED_MODE`, and `VMNET_HOST_MODE`
```yaml
networks:
- vzShared: true
- vzHost: true
```
But, to sharing network between multiple VMs, `VZVmnetNetworkDeviceAttachment` requires VMs are launched by same process.

It depends on Code-Hex/vz#205

Signed-off-by: Norio Nomura <norio.nomura@gmail.com>

# Conflicts:
#	go.sum

# Conflicts:
#	go.sum
Comment thread vmnet/vmnet_darwin.go
Comment on lines +279 to +281
if !netip.MustParsePrefix("192.168.0.0/16").Overlaps(subnet) {
return fmt.Errorf("subnet %s is out of range", subnet.String())
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there any specific reason for limiting to the 192.168.0.0/16 range only? Ideally users should be able to specify any RFC 1918 range, including 10.0.0.0/8 or 172.16.0.0/12 and it doesnt look like apple explicitly prevents this.

Suggested change
if !netip.MustParsePrefix("192.168.0.0/16").Overlaps(subnet) {
return fmt.Errorf("subnet %s is out of range", subnet.String())
}
rfc1918 := []netip.Prefix{
netip.MustParsePrefix("10.0.0.0/8"),
netip.MustParsePrefix("172.16.0.0/12"),
netip.MustParsePrefix("192.168.0.0/16"),
}
allowed := false
for _, r := range rfc1918 {
if r.Overlaps(subnet) {
allowed = true
break
}
}
if !allowed {
return fmt.Errorf("subnet %s is not in an RFC 1918 range", subnet.String())
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

According to the doc, it is a default value.

All other parameters are optional and have the following default value:
...

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, good chance that it supports the same private addresses as the older APIs.

@bubunyo

bubunyo commented Jul 5, 2026

Copy link
Copy Markdown

@norio-nomura any progress here, if you can list some of the changes you are looking for, i am happy to assist i making them and the adding then opening a pr to this.

@s3rj1k

s3rj1k commented Jul 25, 2026 •

Copy link
Copy Markdown

Played with this a bit, specifically with

  • vmnet.NewNetworkConfiguration(vmnet.SharedMode)
  • vz.NewVmnetNetworkDeviceAttachment()
  • netCfg.AddPortForwardingRule()

And I can confirm that at least this flow works fine and there is no need for root if below entitlements are used alongside with --options runtime to codesign

<dict>
    <key>com.apple.security.virtualization</key>
    <true/>
    <key>com.apple.security.cs.allow-jit</key>
    <true/>
    <key>com.apple.security.cs.allow-unsigned-executable-memory</key>
    <true/>
    <key>com.apple.security.cs.disable-library-validation</key>
    <true/>
</dict>

Hoping we get this merged before macOS 27.0 comes out, as it will also ship more new features.


One thing that I've noticed is that AddDhcpReservation kind of unreliable, guest can get different IP, this is fixable with custom cloud-init, but AddDhcpReservation itself enables AddPortForwardingRule, so I am happy this works.

@Code-Hex

Copy link
Copy Markdown
Owner

@norio-nomura Could you share the current status of this PR and what remains before it is ready for review? In February, you mentioned testing the file adapter in Lima and investigating the TSO issue. Are those still the main blockers?

No rush; I want to understand the next steps and whether a smaller part is ready to review separately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants