Skip to content

apple: let virtual machines connect to each other - #7865

Merged
osy merged 3 commits into
utmapp:mainfrom
lovon-spec:apple/vmnet-networking
Sep 19, 2026
Merged

osy merged 3 commits into
utmapp:mainfrom
lovon-spec:apple/vmnet-networking

Conversation

@lovon-spec

Copy link
Copy Markdown
Contributor

Summary

Add two Apple Virtualization networking modes on macOS 26 and later using VZVmnetNetworkDeviceAttachment:

  • Shared Network (VM to VM) puts Apple VMs on the same vmnet shared network so they can communicate with each other while retaining host and internet access.
  • Host Only puts Apple VMs on the same host-only vmnet network so they can communicate with each other and the Mac without internet routing.

The vmnet manager weakly caches one attachment per mode while Virtualization objects own its actual lifetime. Configuration validation stays side-effect-free, so saving a VM does not create a live vmnet network. The new modes also round-trip through UTM's scripting interface and are hidden on older macOS versions.

Resolves #6975.
Related to #7418 and #7380.

Testing

I tested this change on MacBook Pro with Apple M5 Pro running macOS 26.4.1.

  • Shared Network (VM to VM): I started two Apple Virtualization VMs, checked their guest IP configuration, and confirmed direct guest-to-guest SSH connectivity.
  • Host Only: I confirmed guest-to-guest connectivity, connectivity to the host, and verified that internet access was unavailable as intended.

I confirm that this change has been tested and reviewed in accordance with UTM's AI contribution guidelines.

Additional automated application-level verification covered pause/resume, first-user stop/restart, final network release, saved-state restore, concurrent configuration saves, scripting round-trips, network-creation errors without NAT fallback, and the post-start external-drive failure lifetime case.

@ttc0419

ttc0419 commented Sep 18, 2026

Copy link
Copy Markdown

@osy Could you take a look? It's the last missing piece for many users.

@osy

osy commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Patience, there's like a dozen things I have to review.

lovon-spec and others added 2 commits September 18, 2026 13:26
Apple Virtualization's existing Shared Network uses a separate NAT
attachment per VM, so guests cannot use it to reach each other. macOS 26
adds VZVmnetNetworkDeviceAttachment, which lets multiple VMs attach to the
same process-owned vmnet network.

Add two macOS 26+ modes:

- "Shared Network (VM to VM)": guests share a NAT-backed vmnet network and
  can reach each other, the host, and external networks.
- "Host Only": guests share a host-only vmnet network and can reach each
  other and the host without external routing.

UTMAppleVmnetNetworkManager keeps a weak attachment cache per mode while
Virtualization configuration and runtime objects own the attachment and its
native network. The network therefore follows the actual VZ object lifetime
rather than UTM's presentation state, including failure paths where a VZ VM
can remain alive after UTM reports it stopped. Configuration validation uses
a side-effect-free placeholder so saving a VM does not create a live vmnet
network.

Hide both modes before macOS 26 and add matching scripting enumerators and
round-trip parsing.

Resolves utmapp#6975.
Related to utmapp#7418 and utmapp#7380.

Assisted-by: Claude:claude-fable-5-1
Assisted-by: ChatGPT:GPT-6-Pro
Assisted-by: ChatGPT:GPT-5.6-Sol
No delegate callback follows a failed start, restore, or install, so the
VZVirtualMachine created for the attempt was kept until the next start and
the serial port PTYs stayed open and advertised for a stopped VM. With vmnet
networking this also kept the network and its subnet reserved with nothing
running. Drop the virtual machine and close the serial ports in that case,
unless the guest is still alive and will report its own stop.

Assisted-by: Claude:claude-fable-5-1
@osy
osy force-pushed the apple/vmnet-networking branch from 8fad0e4 to 155ad87 Compare September 18, 2026 18:18
@osy

osy commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

@ttc0419 I've made some changes and synced with the latest HEAD. Can you re-test?

@osy osy added this to the v5.0 milestone Sep 18, 2026
@lovon-spec

Copy link
Copy Markdown
Contributor Author

@osy Thank you for the review and the cleanup here! I retested 155ad876 on both macOS 26.4.1 and 27 and found one issue with the preferred addresses.

The short version is that vmnet treats the address we pass as the host/router address for that /24, so using 192.168.96.0 / 192.168.160.0 makes the VM interface fail later during startup. Using .1 instead keeps the same subnets but gives the host a valid address.

I confirmed the two-line .0 → .1 change with a source-built UTM on macOS 27: guest/host connectivity works in both modes, NAT gets internet access, and Host Only stays isolated. The fallback doesn’t catch the current failure because network creation itself succeeds; the interface only fails afterward.
Happy to fold that fix into the existing commit if you want.

Otherwise, the networking and lifecycle paths I retested looked good.

Follow-up to the vmnet networking modes:

- Rename "Shared Network (VM to VM)" to "NAT Network" (config value
  "NATNetwork", scripting term "nat network") so the picker does not offer
  two "Shared" modes that differ only by a suffix.
- Request a fixed subnet per mode outside of the ranges vmnet hands out by
  default. Those ranges are also used by NAT attachments and QEMU, so guest
  addresses depended on what else was running whenever the network was
  (re)created. Fall back to a vmnet chosen subnet when ours is taken.
- Show the mode description with DetailedSection. The bare Text row widened
  the form and clipped the labels and controls in the settings window.
- Only require macOS 26 when a network is actually created, so a VM using
  one of these modes can still be edited and saved on older hosts.
- Do not apply locale digit grouping to the vmnet error code.
- Fold the validation flag into the existing one that skipped drives and
  leave the device unattached instead of using a NAT placeholder, remove
  the unused reverse mapping, key the networks by vmnet_mode_t, and isolate
  the manager to the main actor in place of a lock with no concurrent users.

Use .1 as the host-side address within each preferred /24. As reproduced
in PR utmapp#7865, vmnet accepts .0 during network creation but the interface
fails later at startup.

Assisted-by: Claude:claude-fable-5-1
Assisted-by: ChatGPT:GPT-6-Astra-Pro
@lovon-spec
lovon-spec force-pushed the apple/vmnet-networking branch from 155ad87 to 47eadda Compare September 19, 2026 00:45
@lovon-spec

Copy link
Copy Markdown
Contributor Author

PS: I went ahead and pushed the two-line .0 → .1 fix as 47eadda150b7.

@osy osy linked an issue Sep 19, 2026 that may be closed by this pull request
@osy
osy merged commit be869dd into utmapp:main Sep 19, 2026
27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

host-only networks for non-emulated VMs w/ "Apple Virtualization" Allow VM to VM connections

3 participants