MacVisor Beta

Changelog

MacVisor beta release notes.

MacVisor is beta software. Features and formats can change before 1.0; keep an independent VM backup and review destructive confirmations carefully.

Notes and limitations:

  • MacVisor is mainly developed and tested for single-user Apple-Silicon Macs.
  • MacVisor is specially designed for hosted Mac minis and Mac Studios.
  • Requires macOS 27. The guest agent supports macOS 14 and later inside a VM.

27.0 — public beta

Virtual machines

  • Linux VMs from a signed catalogue of distribution cloud images — Ubuntu 26.04 and 24.04, Debian 13 and 12, Fedora 44 and 43, Rocky Linux 10 and 9, AlmaLinux 10 and 9, Oracle Linux 10 and 9, CentOS Stream 10, openSUSE Leap 16.0, Alpine 3.23. Each image is downloaded once, verified against the vendor's checksum, converted to an ASIF template, and every VM is a linked clone of it.
  • cloud-init sets each one up on first boot: your Mac account (same user name and UID) and SSH keys, the MacVisor agent, a container runtime (containerd with nerdctl by default; Docker, Podman, k3s, or none), your home folder shared read-only at the same path, an optional project folder, Rosetta, and your own #cloud-config.
  • macOS installers from the catalogue (macos-27, macos-26, macos-15, macos-14, macos-latest), downloaded from Apple once and checked against their SHA-256; a local .ipsw is validated as a restore image for virtual Macs. Only the newest build of each macOS version is kept.
  • macOS 27 guests skip Setup Assistant: account mac with password macvisor, automatic login and Remote Login on by default, all changeable in the form (which remembers the last account) or with --user, --password-file, --ssh, --no-autologin, --no-setup. MacVisor installs the MacVisor Agent itself after the first boot and authorises your SSH keys.
  • The New VM form switches Linux | macOS with a segmented control; Linux sources are Cloud Image, Installer ISO, or Template. ISO installs work as before.
  • A saved session macOS can't restore — after heavy load or a macOS update — is reported in plain words with Try Again and Start from Disk; mvz start <vm> --discard-state from the CLI. revert --resume falls back to the snapshot's disk and says so.
  • NVRAM (boot-args) editing for macOS guests in Settings and mvz nvram; macOS 27 currently refuses the private interface, and the UI says so.

Storage

  • Images and installers can be added from a local file — qcow2, raw, .xz, or .ipsw — with mvz images add, the + button next to the Templates search, or drag and drop. The Templates list shows macOS installers too.
  • Downloads show size, speed, and ETA, and resume across interruptions, mvz tasks cancel, and MacVisor restarts. A download in progress sits in Templates/Downloads/<file>.partial inside the storage location; partials nobody returns to are removed after two weeks.
  • mvz images pull fetches a newer vendor build for the "latest" entries; create reuses the template it has.
  • Layer GC: deleting the last linked clone gives a VM its sealed layer back by itself; otherwise the Overview reports the space in disk layers no clone uses, with Flatten Disk. mvz flatten and mvz trim from the CLI.
  • Linked clones, clone-from-snapshot, export, import, move, and storage locations from the CLI.

Networking

  • <vm>.macvisor resolves on the Mac (a responder in the service, reached through /etc/resolver/macvisor); host.macvisor.internal resolves in the guest. mvz ssh-config --install makes ssh dev.macvisor and VS Code Remote-SSH work with pinned host keys.
  • Automatic TCP and UDP forwarding of the ports a cloud-image guest listens on to 127.0.0.1; per-VM forwards take --udp.
  • A Docker socket per VM at ~/.macvisor/run/<id>.docker.sock with a docker context (mvz docker), and k3s kubeconfigs (mvz kubeconfig).
  • The Default MacVisor Network, which new VMs also fall back to when a config names a custom network or bridged interface this Mac doesn't have.
  • Custom networks, reservations, and the firewall from the CLI (mvz networks create|rm|reserve|firewall). Documented vmnet limits on macOS 27: no fixed subnet on shared networks (vmnet re-picks it whenever the network is created, so reservations hold only while it stays), and no DHCP on a host-only network with a fixed subnet.

Guest tools

  • Installed for you: by cloud-init on Linux cloud-image VMs, and by MacVisor over SSH on macOS 27 guests with automatic setup and Remote Login. Manual install remains for ISO installs and macOS 26 and earlier.
  • mvz shell and exec for Linux and macOS guests over the agent's tunnel, as your own account; mvz send for files; mvz wait until the agent answers and cloud-init is done.

Host and automation

  • The CLI is now mvz, short for macvisor; both names are linked at /usr/local/bin by the admin helper. Operations are tasks (list, status, cancel). Shell completion for zsh, bash, and fish (mvz completion).
  • New commands: create from a cloud image, installer, template, disk file, URL, or .ipsw; images (list, pull, add, rm); shell, exec, ssh-config, docker, kubeconfig, wait; set; clone --linked|--snapshot; export, import, move, locations; ip --wait; start --discard-state; disks, nics, trim, flatten, nvram; networks.
  • Exit codes: 0 success, 1 failure, 2 usage error, 3 not found, 4 service unreachable, 5 timed out.

Licensing

  • Two tiers: Professional (one individual, commercial or not) and Business (organisations and CI/CD), both per Mac host, both activated online through Polar once. There are no offline licenses.

0.5.0 — first beta

Virtual machines

  • macOS guests from an IPSW, with optional automatic first-boot account setup; ARM64 Linux guests from an ISO.
  • Separate display windows, headless mode, additional displays for macOS guests, and accelerated graphics.
  • Pause, suspend, resume, restart, shut down, power off, and discard saved state, with confirmation on the destructive ones.
  • Templates, full clones, and linked clones that fork a VM instantly by sharing a sealed ASIF base.

Storage

  • ASIF everywhere. Every disk MacVisor creates uses Apple's sparse format; ASIF disks can grow and shrink.
  • Legacy raw disks keep working and can be converted in place with Convert to ASIF…, with a free-space pre-flight.
  • Multiple storage locations, cold and warm migration, and logical / physical / private size accounting.
  • Disk-only and live snapshots, revert with an optional safety snapshot, clone-from-snapshot, and export. An interrupted revert is completed automatically on the next scan.

Networking

  • NAT, bridged, and named custom vmnet networks, shared or host-only.
  • Per-network DHCP, DNS proxy, NAT44, NAT66, IPv6 router advertisements, address reservations, and TCP/UDP forwards.
  • Host 802.1Q VLAN interfaces, usable for direct bridging or as a shared network's uplink.
  • A per-network IPv4 firewall compiled into a pf anchor by the root helper, re-applied at boot before anyone logs in.

Guest tools

  • MacVisor Agent for macOS and Linux guests over vsock: clipboard, file transfer, live IP information, port tunnels, snapshot filesystem preparation, and clock resync after resume or host wake.
  • macOS guests install by dragging MacVisor Agent onto the Applications alias on the mounted volume and opening it once; it registers its own login item and appears as MacVisor Agent in the guest's Login Items.
  • Linux guests run install.sh once for a systemd unit.

Host and automation

  • A background control service that owns the library and keeps VMs running with no window open, plus one runner process per VM so a failure is scoped to that VM.
  • Auto-start at login, a menu bar item, a live task pane with history, and an Unattended Auto-Start panel that reports every link in the reboot chain.
  • The vz CLI — renamed in 27.0 to macvisor, with mvz as the short alias — linked during first-run setup, covering VMs, templates, snapshots, files, ports, operations, consoles, screenshots, and service control.
  • Problem reports, per-VM runner logs, and a log viewer.

Licensing and updates

  • 30-day local trial with no payment details and no feature limits.
  • Licenses validated once at activation. (The first beta's tiers were replaced by the two-tier Professional / Business model in 27.0.)
  • In-app updates through Sparkle, verified against MacVisor's signing key; running VMs are not interrupted.

Thanks and Credits

  • Sparkle Project for providing an update framework for MacVisor
  • Apple DTS/VZ team for reviewing and granting us the private networking and usb-accessory entitlement