--- name: vm-lab description: Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro. Use to run or inspect an isolated guest. compatibility: Requires a hypervisor (Parallels/VirtualBox/VMware) and SSH to the guest --- # VM Lab - cross-OS debugging on any free hypervisor Disposable local VMs - real macOS, Windows, and Linux, isolated from this host - for cross-OS repro, live process/network/file/memory triage, code-signing checks, and dynamic instrumentation. Works on **Parallels, VirtualBox, or VMware** with **no paid tooling**. ## The core idea **SSH is the universal substrate.** The hypervisor only ever does four things - `list`, `get-ip`, `power`, `snapshot` - and each of the three has a *free* way to do all four (`providers/*.sh`). Everything valuable (the debug toolkit) runs over SSH and is hypervisor-agnostic; it only varies by **guest OS** and **CPU arch**. So this skill is a thin swappable provider layer + a big OS/arch-specific debugging core. ## On every invocation - ask first, then route This skill serves three OSes and three providers. Before doing anything, establish: 1. **Which guest** - macOS, Windows, or Linux? (drives `toolkits/.md` + SSH gotchas) 2. **Which provider** - Parallels / VirtualBox / VMware? (drives `providers/.sh`) 3. **Set up fresh, or use an existing guest?** - *Existing* → confirm it's in `config.local.env`, `./ctl.sh up`, `./verify.sh `, go. - *Fresh* → `bootstrap/` (Path A one-liner, or Path B unattended), then add to config, verify, **snapshot**. If a `config.local.env` already defines the guest the task needs, skip the questions and use it. Ask only what's genuinely unresolved. ## Config & connect All mutable details live in **`config.local.env`** (copy from `config.example.env`; it's gitignored so your IPs/keys never get shared). Then: ```bash source lib.sh # loads config + helpers (rc, rc_sudo, ssh_cmd, prov, ctl) rc mac 'uname -a' # run on the macOS guest rc win 'whoami' # Windows: auto-wrapped as base64 PowerShell rc lin 'uname -a' # Linux rc_sudo mac 'fs_usage -w' # sudo on mac/linux (echoes the guest pw via -S) ./verify.sh # every guest: tools present + callable, with hints ./ctl.sh doctor # host preflight: which providers/tools are present here ./ctl.sh win up # boot + WAIT for sshd; then down|ip|ssh|snaps|vms push mac ./tool /tmp/tool # copy to guest (scp); pull mac /tmp/x.pcap ./ to fetch tun mac -L 8080:127.0.0.1:8080 # port-forward (MITM/reach a guest service) ./ctl.sh mac reset # restore the clean snapshot (RESET_SNAPSHOT) - the disposable loop ``` Guests are tags (`mac`/`win`/`lin`, your choice) with `{PROVIDER, OS, ARCH, VMNAME, IP, USER, AUTH, KEY/PW}`. Leave `IP` blank to auto-discover (provider → mDNS → ARP). **Quoting caveat:** `rc 'cmd'` single-quotes the command, so an embedded `'` breaks it. For anything non-trivial (or with quotes) use **`rcs