Vftool runs Linux virtual machines in macOS Big Sur
github.com
github.com
>> Note This entitlement is restricted to developers of virtualization software. To request this entitlement, contact your Apple representative.
I have not done development in Xcode for some time, but the first thing I wanted to do for an internal project was hamstrung by restricted entitlements. Luckily, it was just an experiment, but it makes it feel like this is coming up a lot. Is there still a way around this (i.e. to run your own code on macOS) ?
This isn’t the first time I’ve seen a project based around Virtualization.framework; that’s both exciting and disconcerting. Issues like entitlement deals (that I will never be able to obtain) make the wide open path forward look a lot like a narrow track, the direction of which only Apple controls.
But I wonder how much 'normal' Apple consumers realize how shoddy some of that custody really is.
I bet your customers blamed you for that bug, not Apple?
As the creator, notify your users about it and there you can blame Apple as long as you want. But if the users are not notified, they don't really know that the creators are waiting for Apple.
Same flawed workflow. Show QR to scanner => not work => check phone on apple pay mode with credit cards => repeat => ask the (human) controllers.
You can ping me @ lucas@concpt.io
When it wasn't scanning and I took my phone off the scanner, I briefly glimpsed the Apple Pay screen before it animated away, so I realised I was "holding it wrong", and was able to get it to scan by holding it at a different angle to keep the NFC sensor at the top of the phone away from reader, but I can imagine a less technically minded user than myself might have serious problems.
I don't know anything about the scanner or NFC standards used by this system, sorry.
It took me a second to realize you weren't talking about the NFC chip, which is codenamed Stockholm ;)
If Apple wants feedback from its developers, it should try actually listening to all of them, not just the ones that make enough noise on social media.
(I'm assuming the parent comment is from someone at Apple. If not, my point still stands in general.)
This isn’t to say HN is a good replacement for a proper support channel, but sometimes you need a little help. These are big companies, so these small issues (for Apple) don’t always make it to the right team. The parent poster here isn’t even the dev of the app in question. How are they supposed to know where to report that?
Did you have your ticket in the Apple wallet or the DB App? I have found that DB Scanners don’t like the wallet version.
This is very handy in Chicago if you are making a single leg journey. Due to Apple Pay’s privacy architecture it can’t recognize transfers and always charges full fare.
The card number of a given card on a given device does not change between taps for Apple Pay. Otherwise, tapping for refunds would not work, among other things.
I don't think this is the case—in London, I'm pretty sure you can pay with Apple Pay and have your fares "capped" (so you never pay more than the price of a full-day ticket). You can also set up an account with your card number (the one on your physical card) and view any recent journeys you've made.
In Big Sur I’ve noticed there’s now a “Developer Tools” entitlement in Privacy. I’m not sure exactly what it allows executables to do, but as it starts off with Terminal.app as a suggested entry, I’d assume it at least allows the given app to spawn unsigned binaries.
Perhaps Apple will figure out some software control to sidestep this administration overhead, or just make it an xtra license to milk more money. After all Microsoft has been doing this since the beginning...
Security is always somewhat like that. It really wouldn't be that hard for a determined burglar to break into my house. I could make it a lot harder, but doing so would come at the expense of a great deal of my own convenience and even freedom. I don't want bars on my windows and I don't want to have to authenticate against a panel or app/keyfob every single time I enter or leave my home.
My neighborhood has police and I live in a very civilized place. The Internet is an open war zone overrun with criminals and malicious privacy-invading corporations (and governments, and not just your own government) bent on subjecting you to a total panopticon. Computers must be secure in a much more hostile environment than my house or my car. A computer today must be more like a hardened compound in a failed state than a house in a typical developed world city or suburb.
I've been saying "the Internet is a failed state" for a while. Apple with its locked down walled garden is like one of those private mercenary security armies that provide security to the rich in failed states.
I don't disagree with the comment's observations, though I don't see a path to get to a "friendly" internet without sacrificing other important freedoms.
However, Virtualization.framework runs out of process, and Apple forgot to check for root if the entitlement isn't present. That should get solved soon.
I can understand the desire, for convenience's sake of testing stuff quickly, to directly virtualize a guest linux OS on a developer's workstation laptop or desktop running MacOS.
But that's an absolute non-starter for me. Contact your sales representative for an entitlement? Forget that, I'll keep on using Linux kernel based virtualization with either xen or kvm, and the equivalent of xen domU PV or HVM on a normal x86-64 server platform, controlled remotely from my laptop, thanks.
The whole language in that sounds like they hired some MBAs away from Oracle.
Seriously though, the machines are open, you can disable all the security to various degrees. The entitlement stuff is for deploying to vanilla Macs with all the codesigning requirements enabled (e.g. via the App Store), for security. It doesn't stop you from bypassing it on your own machines.
https://forums.macrumors.com/threads/if-you-disable-sip-all-...
Your line was my line for a long time. But I feel like this is a significant step. For the first time, by taking control of your own device you’re loosing functionality.
SIP is already fairly flexible, in that it allows you to selectively disable only certain protections (see csrutil's man page). The things people complain about being unable to do without disabling SIP—injecting into other processes, modifying system files, etc—are in fact the exact things SIP exists to prevent.
A lot of Mac users I've talked to, including technical ones who IMO should absolutely know better—appear to be under the impression that disabling any part of SIP will perform voodoo magic that makes them an instant hacker target. This just isn't true. Running `csrutil disable && csrutil enable --without debug` allows mac apps with root privledges to inject code into other processes, nothing more and nothing less. To the extent that allowing code injection is a security risk, this is a security risk. If you want to inject code, turn it off and have fun.
iOS apps are the first time to my knowledge that disabling SIP has actually broken something unrelated. (But do let me know if there's a --without-disabling-fairplay option, I don't have an M1 Mac and there's a dearth of information on this.)
As far as having a trusted computing base, well, I think anyone who believes that's actually possible on a mainstream end-user device is fooling themselves. Jailbreaks already exist, as does Corellium. If you're distributing a private app to employees on company computers, set up an MDM profile which prevents messing with SIP, and schedule regular, in-person device check ups to look for signs of user tampering. In any other situation, assume your software is going to be run in an untrusted environment at some point, because it will be.
> A Boolean that indicates whether the app manages virtual network interfaces without escalating privileges to the root user.
https://developer.apple.com/documentation/bundleresources/en...
Indeed, but why can't it be granted by root?
I agree that the situation is not ideal, but at least you can run it on your own computer if you actually want to...
In the past there were some bad actors doing shady stuff on iOS with this type of entitlement. I wonder if that influenced this type of restriction: https://guce.techcrunch.com/copyConsent?sessionId=3_cc-sessi...
> Releasing this week:
> - Docker Desktop 3.0
> - Docker M1 Mac Technical Preview
...anticipation builds...
https://github.com/evansm7/vftool/issues/2#issuecomment-7354...
as this doesn't seem to work right away for popular options, e.g. I tried the Alpine aarch64 net boot and nothing happens.
Also,.having to rebuild your binary just to run it under docker/linux means you cannot benefit from your compiler cache you just used minutes ago to run your unit tests locally (e.g. if you use tool chains like go or rust that do use compilation caches)
Or IOW is there an equivalent actively maintained?
What’s the diff between Hypervisor and virtualisation frameworks? Docs are ambiguous.
It appears xhyve is built on Hypervisor.framework while vftool is built on Virtualization.framework. Is that the main difference? What does that mean?
https://developer.apple.com/documentation/hypervisor?languag...
Looks like Virtualization.framework is newer (Big Sur only) and uses Objective C classes rather than C functions.
I know from the xhyve README that it contains code responsible for booting a Linux kernel, which suggests Hypervisor.framework does not take care of that for you. The Virtualization.framework API on the other hand takes a linux kernel + ramdisk as its inputs.
So it sounds like the framework vftool is built on is more high-level than that of xhyve, and like vftool is Linux-only.