Quickemu: Quickly create and run optimised Win-10,11/macOS/Linux on Linux
github.com
github.com
Apart from that, I will definitely use that project as a documentation for "how to run MacOS/Windows in KVM". Cool project :) .
https://github.com/wimpysworld/quickemu/blob/af26f41440d63a0...
https://support.apple.com/guide/security/recoveryos-and-diag...
> When the internet recovery and diagnostic modes were added to Mac computers in 2011, it was decided that it would be better to use the simpler HTTP transport, and handle content authentication using the chunklist mechanism, rather than implement the more complicated HTTPS functionality in the UEFI firmware, and thus increase the firmwareʼs attack surface.
¹https://github.com/acidanthera/OpenCorePkg/blob/4a740c3f256e...
[edit] Added macrecovery.py info
Now, apparently this uses plain http - but if tls/https is an option - any client (like curl/wget) should by definition come with a ssl trust root (os or bundled). If this is mitm'ed, you've got big problems. Certificate pinning doesn't really help that much in this case.
The "theft" spin on copyright violation is the result of years of lobbying by the media industry because they foresaw a drop in sales when people didn't need to buy the same thing over and over again.
This still counts as “having control”.
(Caveat: I’m not a lawyer, but I learned broadly the above from an IP lawyer.)
That is not to say that numerous judges have not, on their own initiative, elected to grant holders many such powers. Judges can be just as confused as anyone, and more than some, and so exceed their statutory authority. Congress, moreso. But there is still a difference.
(or they just do it anyway and don't tell Tim.)
I don't think it's true since the phrase in question was present also in Mac OS X when we had to purchase each version. Apart from that, this part of the license is not valid in several European countries. When you think of it, it's quite reasonable: how could anyone dictate how you are using something you purchased? It makes no any sense.
Do you have a link maybe? My quick search found nothing...
If you don't own a Mac, you don't own macOS. If you own a Mac and some other computer(s), you own macOS for the Mac, but not for the computer(s). You might've purchased an upgrade to a newer version of macOS, but if you don't already own a Mac, you don't have something to upgrade, so the upgrade doesn't grant you ownership of macOS.
Now, from a legal point of view, it's a good deal different from (and more complicated than) that, but that's the basic idea. So don't make the mistake of thinking that because Apple gives macOS away for free to Mac owners, and don't use elaborate and onerous copy protection or license-tracking nonsense, that you're entitled to install it on something other than a Mac.
K4HVD...
09 F9 11 02 9D...
I can't believe I remembered that.
In fact the company changed its name to just "Apple" back in 2007. So maybe this doesn't even count.
(1) You supply this value in the "DeviceKey" config parameter
(2) Ensure the "GetKeyFromRealSMC" boolean config parameter is enabled (not sure if it is turned on by default or not). When enabled, VirtualBox retrieves the value from the SMC of your Mac.
Obviously method (2) only works if your host is a Mac. Apple doesn't supply a public API to retrieve this value, so VirtualBox has some code which runs inside a macOS kernel extension, and directly uses the SMC hardware registers to request it. [EDIT: Actually, turns out macOS does have an undocumented API for this – talk to AppleSMC using IOServiceGetMatchingService, IOConnectCallStructMethod, etc – and they use it, but they still fall back to direct hardware access if the API call fails, or if Windows/Linux/etc is the host OS and Apple hardware is detected.] VirtualBox already has a bunch of kexts needed to provide various features, and so this is just a bit more code in one of those kexts.
Option (2) is a lot of extra complexity compared to option (1), but has the advantage of being legally much cleaner. Option (2) only works on Apple hardware, and so by using option (2) Apple's license condition, of only virtualising macOS on Apple hardware, is automatically enforced.
Considering that VirtualBox is from Oracle, and as well as open source, they also sell it as a commercial product, you can understand why Oracle's lawyers want option (2).
From reading the VirtualBox source code [0] – it also automatically enables GetKeyFromRealSMC if it detects Apple hardware, even if the host OS isn't macOS. So, if you install Windows on your Mac, and then create a macOS VM in VirtualBox, it will automatically select option (2) as well. (I think, they actually include the code to talk to the Apple SMC in their Windows and Linux kernel drivers too.)
(Note I haven't actually tried doing this myself, this is just what I gather from the source.)
[0] https://github.com/mdaniel/virtualbox-org-svn-vbox-trunk/blo...
Not needing to run a kext just to retrieve a known hardcoded string seems like a very good reason.
VirtualBox has code to do the above. But it also has code in one of its kexts to do it by talking directly to the hardware, in case (for whatever reason) this API doesn't work; it tries IOKit first and then calls the kext as a fallback. And, the kext doesn't solely exist to talk to the SMC, it does a bunch of other things too. I'm not sure whether VirtualBox works without its kexts, but if it doesn't, it isn't because of this reason.
(When I wrote my original comment above, I didn't know you could do this through the IOKit API, although I've since edited that comment to mention it.)
disclaimer: I am not a lawyer, this is not legal advice, etc.
Seems people really avoid saying the value, ('don't be surprised it doesn't look like a random string') maybe there's some history of Apple requesting people cease & desist wherever they find it, I don't know.
https://github.com/search?q=isa-applesmc&type=code
I'm guessing it's more of a philosophical stance rather than avoiding detection. Like "Apple isn't going to make me put the string 'dontsteal' in my repo".
Just install proxmox on a mac mini or old mac pro and run macos VMs
While it doesn't have telemetry and you can run it as a VM (arguably the better choice, given it's state), it is not Windows 10 by any stretch, and I guess it doesn't run the latest IE version (but I haven't tried it in ages)
Seems functional and depends on how much you trust the guys behind it. (or compile your own)
Another option is to buy a ltsc win10 license (if you can find it cheap online)
I use the Windows Insider program to run legitimate Windows, and used a bunch of debloat/decrapify programs from Github to try to remove the worst offenders. But damn does Windows Defender and some of the other stuff really ream my resources, and there doesn't seem to be any easy way of permanently disabling them =(
I'd never heard of an "LTSC" Windows either. Interesting.
---
EDIT: Ahh it says there's no support for DirectX12, only Vulkan?
I don't know much about this stuff -- I thought it was a software SDK you could just install. But if not, that seems like a pretty huge con:
https://wiki.ameliorated.info/doku.php?id=faq#is_directx_12_...
I found that to be the "best" performing, although still leaves a lot to be desired and having to open the application, manually sign kernel drivers and then reboot after every kernel upgrade is a little tiresome.
The second problem is getting those pixels onto your screen in the host. SPICE is not as fast as Looking Glass [2], which sets up a shared memory buffer between the host and guest. This has acceptable performance even for modern games.
The OP doesn't seem to utilize these techniques, so I don't think it can plausibly claim to have the fastest configuration - at least not yet.
I tried setting up qemu once by downloading many images. Almost none worked with apps I wanted to run. Also I had a very hard time finding a sane qemu documentation in one place. It's wiki is very messy to go through.
So is there anything to run win 98 to win xp apps in emulator/sandbox/container easily?
I have tried to use it a few times but got overwhelmed by all the options. From the screenshot it looks exactly what I want (only for windows 98 though).
edit: from another comment thread here, https://ameliorated.info/ is apparently everything you're after. Not sure of any info about it myself but that looks to be decently useful.
All this autodetection of the OS to apply tweaks and workarounds to make the OS run properly should ideally be eliminated entirely, and if that really isn't possible, it should be part of Qemu itself rather than requiring a special wrapper script to apply the right flags to make things work.
Nothing stops someone overriding some or all of those flags to whatever values they like. It's still a power user tool, just one that also 'just works' for common usecases of people who don't want to manually set the IRQ number for the DMA controller by hand...
That would add a ton of new responsibility to a codebase that so far has been doing none of this. It would have to be aware of different operating systems, operating system image formats for autodetection, OS releases and their corresponding quirks, ... And some way to test this, and test this automatically, so that this stuff doesn't immediately rot away. People would begin to depend on this, and any change in this behaviour would be a breaking bug, and would introduce implicit stability contracts for complex scenarios.
Let qemu be low-level emulator and make zero assumptions about how it's being used - that makes life so much easier for those of us who integrate it into non-standard scenarios. Libvirt gives you everything needed for typical 'I wanna run a commercial OS in a VM on my desktop/server', and can afford to make assumptions about its usage scenario.
The last I heard about the macos situation is that virtualisation of macOS is allowed as long as you do it on Apple hardware that you have a license to run macOS on. You can run as many virtual machines on your mac as you want, as long as you've paid for the OS on your mac, which you can't buy separately anymore (making any restrictions on licenses a full ban on macOS VMs, which nobody wants). Perhaps you could buy additional licenses through second hand shops, depending on your jurisdiction.
As for legal ramifications, I don't think either Microsoft or Apple will care if you use this for your personal projects. Don't try this as a business, though, because that's where the lawyers start caring.
Legally, you'll probably be liable for a civil lawsuit from either Apple or Microsoft. I don't think it's actually considered a crime to run a copy of software without a license in most countries.
No, the EULA says:
> (iii) to install, use and run up to two (2) additional copies or instances of the Apple Software within virtual operating system environments on each Mac Computer you own or control that is already running the Apple Software, for purposes of: (a) software development; (b) testing during software development; (c) using macOS Server; or (d) personal, non-commercial use.
Does that mean Apple Hardware -> Linux -> macOS is not allowed? Or is it simply saying that all 3 copies must be on the same machine? So you can run Apple Hardware -> Linux -> macOS as your "primary copy" and two more macOS VMs on that same Apple Hardware?
In other words, for an individual (vs. a "commercial enterprise or educational institution"), both of the following appear to violate the license:
(1) Downloading Big Sur from the Mac App Store using a machine running Big Sur itself, for any purpose: the virtualization section 2B(iii) expressly excludes the term "download" from the phrase "download, install, use and run", and, while the other section 2B(i) applicable to individuals does permit downloads, it only applies to computers running Catalina, Mojave, High Sierra, Sierra, El Capitan, Yosemite, Mavericks, Mountain Lion, or Lion.
(2) Using Big Sur for any commercial purpose, e.g., working from home as an employee, or non-personal purpose, e.g., producing flyers for a school bake sale.
I don't recall anyone, including well known retailers selling the OEM version of Windows to home users, caring about it.
I'm not against tooling like this, but as someone already pretty familiar with KVM... I think I'd be quicker with virsh as I've been operating
Vagrant is an orthogonal tool to this, it is a VM orchestrator not an actual VM. What does this do: well, qemu doesn't have virgl support merged yet, so you need to go to some lengths to compile it for yourself.
All of the other stuff (spice, virtio) is for "it should be a nice user experience and perform well" above and beyond simply being fast enough to use. In other words, you should be able to copy and paste between the host OS and the guest. You should be able to slide your mouse across the border of the VM window and do some clicking around then simply slide it back out and use your mouse with native host-OS windows again. It should have all of the features you expect and not force you to read a bunch of tutorials to find the features you expect from your desktop VM.
These things are all not granted when you use qemu out of the box. I have this intense 25-lines "qemu" script for invoking qemu-system properly. It was enlightening but I'm not sure how much I was enriched by the process of actually figuring all this out.
Quickemu is, I guess, for making figuring out all this stuff and making it easier to do (and on Linux.)
Do you have your script posted publicly somewhere?
This expects you're using the special qemu from the prior link, compiled with homebrew. (else I think there will be no virtio-vga-gl video driver?)
The guest OS is an Ubuntu VM. I think the instructions say to use a recent Fedora/Silverblue for a reason (there are some things that don't quite work right around window resizing.)
Each time I start the VM, it shows up with tiny tiny pixels and the menubar does not work. I switch to another app, switch back, go to the menu and enable "zoom to fit" and it's off to the races. Other things to be aware of, if you resize the window it actually scales the pixels, (which is OK and doesn't even have any noticeable perf impact because OpenGL, I guess)
Does anyone know what how to type special keys, like ctrl-alt-delete, in qemu/quickemu?
Common QEMU frontends may have a UI button or keyboard sequence to do this for you (they connect to the monitor backend and send the same command, either as text or as JSON (in "qmp" mode)).
Certainly, however, this can be handy if one needs to quickly spin up something.
I do wonder if it can use KVM directly instead of QEMU (I can always move the .qcow after, just curious as to how it would work with virsh)
For windows alone I wonder as windows do allow no activation (other than …) and should it ok?
Windows activation servers were happy enough with that, without any install becoming unactivated (other than the VirtualBox to VMware conversion which is the 3rd activation).
While you can use Windows unactivated but it restricts access to various settings, which may not be important to you depending on your use case.
Vagrant depends on premade boxes normally built with packer.
This tool is much more convenient
I’m using several packer templates and prebuilt vagrant boxes and vagrant’s workflow is much better than this strange NIH tool.