rfswift usb

Attach and detach USB devices on macOS (Lima) and Windows (usbipd-win).

Reference · 3 min read · Updated September 27, 2026

On macOS and Windows, containers run inside a virtual machine that cannot see your USB ports on its own. rfswift usb forwards a device (an SDR, a Proxmark3, a serial adapter) into that machine so your containers and Nix environments can use it.

  • macOS: it drives USB hot-plug in the Lima VM.
  • Windows: it drives usbipd-win into WSL 2.
  • Linux: there is no attach step. Devices are mapped when the container is created.
bash
rfswift usb attach      # shows a picker of your USB devices

Synopsis

bash
rfswift usb list                                  # host USB devices
rfswift usb attach --vid 0x1d50 --pid 0x604b      # forward into the Lima VM (picker when omitted)
rfswift usb detach --vid 0x1d50 --pid 0x604b      # or --devid usb-1d50-604b
rfswift usb vm-devices                            # what the VM currently sees
rfswift usb status                                # Lima VM readiness for passthrough

Install Lima once with brew install qemu lima. The VM is created and started the first time you use --engine lima.

For a device to work, two things are needed: the device must be attached to the VM, and the container must run with --engine lima. Docker Desktop and Podman machine cannot receive USB devices.

Details: macusb, engine lima.

Inside the container

A forwarded device can be opened only when both of these are true:

  • /dev/bus/usb is mapped into the container;
  • USB device major 189 is allowed (c 189:* rwm).

Both are part of the RF Swift defaults, and privileged mode is not required. A bare bind mount is not enough: it lists the device nodes, but opening them fails with “Permission denied”.

rfswift container create and the Workbench mission form check this before creating the container and tell you what is missing. The Workbench offers Apply USB hotplug defaults to fix it in one click.

On Windows, rfswift container create, container shell and env shell open the usbipd picker themselves when they detect shared or known RF hardware; ordinary keyboards and webcams never trigger it. The Workbench offers the same as USB passthrough… on Docker, Podman and Nix missions.