What an awful blog renderer that, in Firefox, works when scrolling with the trackpad, but doesn't work when using keyboard arrow keys or pageUp/down: I get blank pages when scrolling with the keyboard beyond the initial viewport.
Rebuilding MicroVMs natively on Apple Silicon usually cuts virtualization overhead massively, but Hypervisor.framework DX and virtio device parity are the real bottlenecks.
Because prices? Have you seen how much Apple products cost these days?
Also, M1/M2 are perfectly fine and capable hardware. It's hard to justify the upgrade outside some artificial constraints Apple would bring in with a macOS update.
You’d be surprised. I got an absolute boat anchor of a 2019 MacBook when I started a job in early 2022. I requested a new one in late 2023 because company policy is to refresh laptops every 4 years - whoever was on the other end of my support ticket interpreted the policy as four years from issuance and denied me.
I'm very surprised you feel it's a given that every SWE at every company has the perk of getting a new machine as quickly as every 2 years, I doubt it's justified by the productivity increases of just 2 years of hardware improvements.
it's pretty common to be running a 4 year old computer in most companies I've worked.
I think they plan for 3 years but in reality it becomes closer to 4 (because they don't plan the refresh during the actual hardware refresh cycle, so you'll end up with a computer that was released in September the year before in like August the year after).
I've never worked anywhere that replaced my computer after 2 years.
Things were painful in the Intel era but I’m on M1 Mac and I’d have a really hard time justifying a request for an upgrade. I absolutely detested my old Intel MacBook (touchbar era) and couldn’t wait to get rid of it.
I run bloated slow electron apps and chrome all day, generally with profligate usage patterns, and things hardly ever slow down even with corporate antimalware. Sometimes I forget about having left Windows VMs running in the background.
Anyway, why would my company spend $2500+ every two years to turn instant into instant?
By experience, getting Firecracker to run well on M-series macs is quite the undertaking. I'm not at all surprised Encore decided to take this path considering their customer base!
At Lovable we decided to spend ~1 engineering month getting our sandbox infrastructure to be 100% runnable on Mac and on Linux with predictable builds using Bazel etc.
But we actively decided to take a different route than Encore and run nested virtualization, which on macOS means vfkit -> QEMU -> Kind + Firecracker vm(s). It's been invaluable to get the same development and testing tools on both platforms tbh.
Virtualization.framework isn't particularly limited, for what it is... given they're using Firecracker on Linux, it makes sense to use a similarly high level API on macOS.
(One could add a Hypervisor.framework backend to Firecracker, though I'd be surprised if AWS accepted it.)
Plus show me an off the shelf solution to MDM that exists in the Linux space?
(Not too mention an easy to buy consumer devices which supports suspend/resume correctly in 2026, not even Windows can do that any more)
Apple is crap and evil about many things, but at least here they know their paying audience...
One case where Apple can be very useful is if you're traveling a lot for work.
Wherever you are you can probably find a local store that sells and services Macbooks. So if your machine is damaged during a trip you can get it fixed, or buy a replacement on the spot, and at least get through the work you are there to do.
For small-ish companies that can be a very useful feature.
Buying on the spot - sure. Anything that requires repair has to be usually booked in advance with some waiting time. Relatively short, usually days, but still not really possible to go into the store and get your laptop fixed right away in most cases.
Four years on a shared remote machine before building the local backend is a good lesson in when to invest in dev tooling versus living with the workaround.
I just encountered the `com.apple.private.virtualization` entitlement limitation just last night, wanting to use VZVirtualMachine private AccessorEndpoint api. There's lot of useful stuff hidden in Apple's Private API space.
Great write up! I enjoy seeing others working in the same problem space.
I'm very confused why any SWE is on a M1 or M2 Mac. I've always gotten a new machine at $CORP every 2 years...
Also, M1/M2 are perfectly fine and capable hardware. It's hard to justify the upgrade outside some artificial constraints Apple would bring in with a macOS update.
I haven’t asked because my current laptop is more than ok.
I think they plan for 3 years but in reality it becomes closer to 4 (because they don't plan the refresh during the actual hardware refresh cycle, so you'll end up with a computer that was released in September the year before in like August the year after).
I've never worked anywhere that replaced my computer after 2 years.
I run bloated slow electron apps and chrome all day, generally with profligate usage patterns, and things hardly ever slow down even with corporate antimalware. Sometimes I forget about having left Windows VMs running in the background.
Anyway, why would my company spend $2500+ every two years to turn instant into instant?
At Lovable we decided to spend ~1 engineering month getting our sandbox infrastructure to be 100% runnable on Mac and on Linux with predictable builds using Bazel etc.
But we actively decided to take a different route than Encore and run nested virtualization, which on macOS means vfkit -> QEMU -> Kind + Firecracker vm(s). It's been invaluable to get the same development and testing tools on both platforms tbh.
(One could add a Hypervisor.framework backend to Firecracker, though I'd be surprised if AWS accepted it.)
They are solving the wrong problem.
Plus show me an off the shelf solution to MDM that exists in the Linux space? (Not too mention an easy to buy consumer devices which supports suspend/resume correctly in 2026, not even Windows can do that any more)
Apple is crap and evil about many things, but at least here they know their paying audience...
Wherever you are you can probably find a local store that sells and services Macbooks. So if your machine is damaged during a trip you can get it fixed, or buy a replacement on the spot, and at least get through the work you are there to do.
For small-ish companies that can be a very useful feature.
You don't even have to be a large corp for that, my org was 60 people with like 20 Macbooks and we had it.
FWIW if you live in a major metro area, Dell also does this, it's not terribly uncommon for business class machines.
Buy any laptop, stick Linux on it, get working.
Buy a cheap shitty Chromebook, ssh to your dev platform, give it to some school child who doesn't have a laptop when you get your real one back.
You don't need to be locked into Apple's ecosystem for that.
Great write up! I enjoy seeing others working in the same problem space.