9 ms·
Anthropic Cowork feature creates 10GB VM bundle on macOS without warning
- bachittle 7mo agoYup it uses Apple Virtualization framework for virtualization. It makes it so I can't use the Claude Cowork within my VMs and that's when I found out it was running a VM, because it caused a nested VM error. All it does is limit functionality, add extra space and cause lag. A better sandbox environment would be Apple seatbelt, which is what OpenAI uses, but even that isn't perfect: https://news.ycombinator.com/item?id=44283454 https://news.ycombinator.com/item?id=44283454
- j16sdiz 7mo agoseatbelt is largely undocumented.
- pluc 7mo agojust ask AI to document it
- ramoz 7mo agoNot sure why you're getting down voted. This is totally reasonable.
- bachittle 7mo agoOpenAI Codex CLI was able to use it effectively, so at least AI knows how to use it. Still, its deprecated and not maintained, Apple needs to make something new soon.
- ctmnt 7mo agoI don’t have an opinion on how they should handle the nested VMs probably, but I very much disagree that Seatbelt is better. Claude Code (aka `claude`) uses it, and it’s barely good for anything. Out of curiosity, why are you running Cowork inside a VM in the first place? What does that get you that letting Cowork use its own VM wouldn’t?
- blitzar 7mo agoThe vibe coding giveth and the the vibe coding taketh away, blessed be the vibe coding
- MarleTangible 7mo agoIt's incredible how many applications abuse disk access. In a similar fashion, Apple Podcasts app decided to download 120GB of podcasts for random reason and never deleted them. It even showed up as "System Data" and made me look for external drive solutions.
- chuckadams 7mo agoSomeone actually still uses the built-in podcasts app?
- Angostura 7mo agoIt's absolutely fine, from what I can tell
- mister_mort 7mo agoAFAIK the native Podcast app for iPhone is the only way to make PC-phone podcast file syncing work. This stops you downloading the same podcast file twice, once on your PC and once on your phone.
- hidelooktropic 7mo agoNot sure what you have against it. Works great for me. No subscription required. And if I do want to pay for ad free shows and support creators it's easy to do so. Use whatever you like but I don't think Podcast app users are rare by any stretch of the imagination.
- dewey 7mo agoIt probably has more active users than all third party podcast apps on all mobile platforms combined. The power of defaults.
- rafram 7mo agoIt's generally a good app. People in the tech community like Overcast, but I've always found its UI completely illogical. Apple Podcasts is organized like I'd expect a podcast app to be.
- 7mo ago
- tbrownaw 7mo agoSure it uses a few GB just like everything else these days, but some of the comments also mention it being slow?
- Aurornis 7mo agoThe GitHub issue is AI generated. In my experience triaging these in other projects, you can’t really trust anything in them without verifying. The users will make claims and then the AI will embellish to make them sound more important and accurate.
- dylan604 7mo ago> AI will embellish to make them sound more important and accurate. Did you mean than accurate rather than and accurate? Having a more accurate issue description only sounds like a good thing to me
- Filligree 7mo agoTo make them sound more accurate.
- seanhunter 7mo agoI read that as "make them sound more important and accurate than they actually are".
- monsieurbanana 7mo agoMaking them look more accurate is not the same as being more accurate, and llms are pretty good at the former. Imagine a user had a vague idea or something that is broken, then the LLM will choose to interpret his comment for what it thinks is the most likely actual underneath problem, without actually checking anything.
- torben-friis 7mo ago“Seem important and accurate” is correct. It doesn’t imply actual accuracy, the llm will just use figures that resemble an actual calculation, hiding they are wild guesses. I’ve run into the issue trying to use Claude to instrument and analyze some code for performance. It would make claims like “around 500mb ram are being used in this allocation” without evidence.
- Aurornis 7mo agoThis GitHub issue itself is clearly AI slop. If you’ve been dealing with GitHub issues in the past months it will be obvious, but it’s confirmed at the end: > Filed via Claude Code I assume part of it is true, but determining which part is true is the hard part. I’ve lost a lot of time chasing AI-written bug reports that were actually something else wrong with the user’s computer. I’m assuming the claims of “75% faster” and other numbers are just AI junk, but at least someone could verify if the 10GB VM exists.
- chuckadams 7mo agoI wouldn't think it's inappropriate for an AI agent to file an issue against another AI agent, which itself is largely written by AI.
- 16bitvoid 7mo agoIf your codebase is entirely vibe coded, I feel it only appropriate to permit issues being vibed as well. It's hypocritical otherwise.
- rzzzt 7mo agoUse an agent to summarize and generate reproducers for each report, another to select issues to be fixed in the next iteration, a third one to implement changes, a fourth for code review...
- fragmede 7mo agoWhat's funny is interacting with it in claude code. Claude-desktop-cowork can't do anything about the VM. It creates this 10 GiB VM, but the disk image starts off with something like 6-7 GiB full already, which means any of the cowork stuff you try to do has to fit into the remaining couple of gigs. It's possible to fill it up, and then claude cowork stops working. Because the disk is full. Claude cowork isn't able to fix this problem. It can't even run basic shell commands in the VM, and Opus4.6 is able to tell the user that, but isn't smart enough/empowered to do anything about it. So contrary to the github issue, my problem is that it's not enough space. So the fix is to navigate to ~/Library/Application\ Support/Claude/vm_bundles, and then ask Claude Code to upsize the disk to a sparse 60 GiB file, giving cowork much more space to work in while not immediately taking up 60 GiB. Bigger picture, what this teaches me though, is that my knowledge is still useful in guiding the AI to be able to do things, so I'm not obsolete yet!
- pixl97 7mo agoSo it's using it's binary disk/image as the cache/work disk also? Yea, that's a receipt for problems.
- quanwinn 7mo agoI imagined someone at Anthropic prompted "improve app performance", and this was the result.
- andresquez 7mo agoWay slower, but way better than chat mode. Nothing beats Claude Code CLI imo.
- informal007 7mo agoI believe that employees in Anthropocs use CC to develop CC now. AI really give much user ability to develop a completed product, but the quality is decreasing. Professional developers will be in demand when the products/features become popular. First batch of users of new products need to take more responsibility to test the product like a rats in lab
- deleted 7mo ago[deleted]
- deleted 7mo ago[deleted]
- deleted 7mo ago[deleted]
- rvz 7mo ago> AI really give much user ability to develop a completed product, but the quality is decreasing. Professional developers will be in demand when the products/features become popular. Looking at the amount of issues, outages and rookie mistakes the employees are making leads me to believe that most of them are below junior level. If anyone were to re-interview everyone at Anthropic for their own roles with their own interview questions, I would guess that >75% of them would not pass their own interviews. The only team the would pass them are the Bun team and some other of the recently acquired startups.
- linkregister 7mo agoClaude consistently tops the leaderboard in software engineering benchmarks.
- rvz 7mo agoYou realise that excuse is completely irrelevant? For the outages and the rest of the issues above and even when it goes down you still need to know what exactly is wrong. Using 'software engineering benchmarks' and 'leaderboards' to mask for those issues in scenarios that require rapid response or urgency doesn't make any sense and even going with that, I would expect less outages but it is in fact the opposite, especially when what we are seeing is that one outage occurrs, another one appears right afterwards almost the next day.
- game_the0ry 7mo agoYeah, that's why I do not install these tools on my personal devices anymore and instead play with them on a VPS. Try this if you have claude code -- ls -a your home dir and see all the garbage claude creates.
- atonse 7mo agoI literally spent the last 30 mins with DaisyDisk cleaning up stuff in my laptop, I feel HN is reading my mind :) I also noticed this 10GB VM from CoWork. And was also surprised at just how much space various things seem to use for no particular reason. There doesn't seem to be any sort of cleanup process in most apps that actually slims down their storage, judging by all the cruft. Even Xcode. The command line tools installs and keeps around SDKs for a bunch of different OS's, even though I haven't launched Xcode in months. Or it keeps a copy of the iOS simulator even though I haven't launched one in over a year.
- puppymaster 7mo agomacbook pro m4 bought last year. worked on so many codes and projects. never hot after closing lid. installed electron claude. closed lid and went to sleep and woke up to macbook that has been hot all night. uninstall claude. problem went away. i kept telling myself this BUT NEVER ELECTRON AGAIN.
- hulitu 7mo ago> woke up to macbook that has been hot all night this is usual reason for divorce /s
- DauntingPear7 7mo agoIt’s not electron
- rvz 7mo agoYes it certainly is.
- woadwarrior01 7mo agoThe macOS Claude app is absolutely an electron app, which is what the github issue in this post is about. If you'd like to verify for yourself: On your mac, right click on the Claude app icon and click on "Show Package Contents" and then navigate to Contents > Frameworks > Electron Framework.framework.
- bigyabai 7mo agoI don't know if Electron is the issue here, my Wintel machine has Claude Code running 24/7 and doesn't ever heat up. Might be virtualization woes or something adjacent.
- lxgr 7mo agoTo be fair, ChatGPT seems to be a native app and still somehow managed to continuously burn some 30-40% of CPU on my mac that ended up being attributable to some shimmer animation for two never-loading icons.
- fooker 7mo agoThat seems somewhat reasonable. Storage should be cheaper, complain about Apple making you pay a premium.
- crumpled 7mo agoThe software seems to get into more and more and communicate about what it's doing less and less. That's the crux. Pondering... Noodling... Some other nonsense...
- mixdup 7mo agoAll code in Claude™ is written by Claude™
- jFriedensreich 7mo agoIts just another example and just a detail in the broader story: We cannot trust any model provider with any tooling or other non model layer on our machines or our servers. No browsers, no cli, no apps no whatever. There may not be alternatives to frontier models yet, but everything else we need to own as true open source trustable layer that works in our interest. This is the battle we can win.
- prmph 7mo agoWhy don't people form cooperatives, contribute to buy serious hardware and colocate them in local data centers, and run good local models like GLM on them to share?
- jFriedensreich 7mo agoWe are starting to! TBH it will take some time until this is feasible at larger scale but we are running a test for this model in one of my community groups.
- jug 7mo agoAlso apparently eating 2 GB RAM or so to run an entire virtual machine even if you've disabled Cowork. Not sure which of this is worse. Absolute garbage.
- kordlessagain 7mo agoThe amount of bad things this companies software does is staggering. The models are amazing, the code sucks.
- AlexeyBrin 7mo agoTheir code is written by their amazing models (this is what they claim anyway).
- bear3r 7mo ago[dead]
- Terretta 7mo agoArguably, even without LLM, you too should be dev-ing inside a VM... https://developer.hashicorp.com/vagrant https://developer.hashicorp.com/vagrant is still a thing. The market for Cowork is normals, getting to tap into a executive assistant who can code. Pros are running their consumer "claws" on a separate Mac Mini. Normals aren't going to do that, and offices aren't going to provision two machines to everyone. The VM is an obvious answer for this early stage of scaled-up research into collaborative computing.
- messh 7mo agoYeah, very easy to do today. May VPS providers help with this, checkout: https://exe.dev https://exe.dev https://sprites.dev https://sprites.dev https://shellbox.dev https://shellbox.dev
- Terretta 7mo agoYes! Whether VPS or local VM, this is a thing for good reasons. Some reasons aren't even optional. Small but regulated entities exist, and most "Team" sized businesses aren't in Google apps or "the cloud" as they think about it, but are in M365, and do pay for cyber insurance. Cowork with skills plugins that leverage Python or bash is a remarkably enabling framework given how straightforward it is. A skill engineer can sit with an individual contributor domain expert, conversationally decompose the expert's toil into skills and subcommands, iterate a few times, and like magic the IC gets hours back a day. Cowork is Agents-On-Rails™ for LLM apps, like Rails was to PHP for web apps. The VM makes that anti-fragile. For any SaaS builders reading this: by far most white collar small business work is in Microsoft Office. The scarce "Continue with Microsoft" OIDC reaches more potential SMB desks than the ubiquitous "Continue with Google" and you don't have to learn the legacy SAML dance. Anthropic seems to understand this. It's refreshing when a firm discovers how to cater to the 25–150 seat market. There's an uncanny valley between early adopters and enterprise contracts, but the world runs on SMBs. Sign them all up!
- mihaelm 7mo agoI prefer devcontainers for more involved project setups as they keep it lighter than introducing a VM. It’s also pretty easy to work with Docker (on your host) with the docker-outside-of-docker feature. However, I’m also curious about using NixOS for dev environments. I think there’s untapped potential there.
- TheRealPomax 7mo agolabelled "high priority" a month ago. No actual activity by Anthropic despite it being their repo. I'm starting to get the feeling they're not actually very good at this?
- pama 7mo agoAren't most these people recommending random tools in the github chat for this entry just attempting to exploit naive users? Why would anyone in this day and age follow advice of new users to download new repos or click at random websites when they already attempt to use claude code or cowork?
- nhubbard 7mo agoWhile I generally agree with your sentiment, these tools aren't bad ones: - Santa is a very common tool used by macOS admins to lock down binary and file access privileges for apps, usually on managed machines - Disk Inventory X and GrandPerspective are well-known disk space usage tools for macOS (I personally use DaisyDisk but that requires a license) - WizTree and WinDirStat are very common tools from Windows admin toolkits The only one here I can say is potentially suspect is ClearDisk. I haven't used it before, but it does appear to be useful for specifically tracking down developer caches that eat up disk space.
- felixrieseberg 7mo agoHi, Felix from Anthropic here. I work on Claude Cowork and Claude Code. Claude Cowork uses the Claude Code agent harness running inside a Linux VM (with additional sandboxing, network controls, and filesystem mounts). We run that through Apple's virtualization framework or Microsoft's Host Compute System. This buys us three things we like a lot: (1) A computer for Claude to write software in, because so many user problems can be solved really well by first writing custom-tailored scripts against whatever task you throw at it. We'd like that computer to not be _your_ computer so that Claude is free to configure it in the moment. (2) Hard guarantees at the boundary: Other sandboxing solutions exist, but for a few reasons, none of them satisfy as much and allow us to make similarly sound guarantees about what Claude will be able to do and not to. (3) As a product of 1+2, more safety for non-technical users. If you're reading this, you're probably equipped to evaluate whether or not a particular script or command is safe to run - but most humans aren't, and even the ones who are so often experience "approval fatigue". Not having to ask for approval is valuable. It's a real trade-off though and I'm thankful for any feedback, including this one. We're reading all the comments and have some ideas on how to maybe make this better - for people who don't want to use Cowork at all, who don't want it inside a VM, or who just want a little bit more control. Thank you!
- Fraaaank 7mo agoI wasn't aware that this VM was created. If this was communicated in the marketing I probably would've started using cowork sooner.
- xvector 7mo agoCowork has been an insane productivity boost, it is actually amazing. Thank you!
- beej71 7mo agoI think these are are excellent points, but the complaint talks about significant performance and power issues.
- wutwutwat 7mo ago
- cogman10 7mo agoOk, so a lot of this boils down to the fact that this sort of software really wants to be running on linux. For both windows and mac, the only way to (really) do that is creating a VM. It seems to me that the main issue here is painful disconnects between the VM and the host system. The kernel in the VM wants to manage memory and disk usage and that management ultimately means the host needs to grant the guest OS large blocks of disk and memory. Is anyone thinking about or working on narrowing that requirement? Like, I may want the 99% of what a VM does, but I really want my host system to ultimately manage both memory and disk. I'd love it if in the linux VM I had a bridge for file IO which interacted directly with the host file system and a bridge in the memory management system which ultimately called the host system's memory allocation API directly and disabled the kernels memory management system. containers and cgroups are basically how linux does this. But that's a pretty big surface area that I doubt any non-linux system could adopt.
- lxgr 7mo agoGiven that Claude Code runs without issues on macOS, I'd guess that it's more about sandboxing shell sessions (i.e. not macOS applications or single processes, for which solutions exist). Unfortunately, unlike Linux, macOS doesn't have a great out-of-the-box story there; even Apple's first-party OCI runtime is based on per-container Linux VMs.
- cogman10 7mo agoI think only BSD really has a good sandboxing solution beside linux (jails). And after looking into Jails, it looks like BSD also supports linux cgroups... that's actually really impressive. [1] [1] https://docs.freebsd.org/en/books/handbook/linuxemu/#linuxemu https://docs.freebsd.org/en/books/handbook/linuxemu/#linuxem...
- jjfoooo4 7mo agoThe upgrade to the native installer gave me some issues, I had Claude fail to return any responses and continuously eat memory until my computer crashed! The only fix I could figure out is nuking my entire .claude dir, losing all my history etc with it
- zhyder 7mo agoI guess it could warn about it but the VM sandbox is the best part of Cowork. The sandbox itself is necessary to balance the power you get with generating code (that's hidden-to-user) with the security you need for non-technical users. I'd go even further and make user grant host filesystem access only to specific folders, and warn about anything with write access: can think of lots of easy-to-use UIs for this.
- brunooliv 7mo agoI really love Anthropic's models, but, every single product/feature I've used other than the Claude Code CLI has been terrible... The CLI just "sticked" for me and I've never needed (or arguably looked in depth) any other features. This for my professional dayjob. For personal use, where I have a Pro subscription and adventure into exploring all the other features/products they have... I mean, the experience outside of Claude Code and the terminal has been... bad.
- yuppiepuppie 7mo agoI tend to agree here. Today, I tried to get the claude chat to give me a list of Jira tickets from one board (link provided) and then upload it to notion with some additional context. It glitched out after trying the prompt over again 4x. I eventually gave up and went back to the terminal.
- perbu 7mo agoYes. This is my experience as well. The software quality is generally horrible. It surely has improved a lot over the last couple of months, but it is still pretty horrible. It is quite normal for me to have to force-close Claude Desktop.
- msp26 7mo ago> every single product/feature I've used other than the Claude Code CLI has been terrible yeah they're shipping too fast and everything is buggy as shit - fork conversation button doesn't even work anymore in vscode extension - sometimes when I reconnect to my remote SSH in VSCode, previously loaded chats become inaccessible. The chats are still there in the .jsonl files but for some reason the CC extension becomes incapable of reading them.
- throwaway613746 7mo ago[dead]
- exabrial 7mo agoI see this as a feature. The cost of isolation
- anotheryou 7mo agoMac Problems... so crazy on a windows desktop I at most complain if it is hardcoded to the system drive (looking at you ollama)
- creatonez 7mo agoAs much as an inconvenience this may be, this is exactly what "agents" should be doing. If your tool doesn't have a builtin sandbox that is intended to be used at all times, you're using something downright hazardous and WILL end up suffering data loss.
- deleted 7mo ago[deleted]
- elzbardico 7mo agoThis is exactly the kind of issues we will see more and more frequently with vibe-coding.
- Robdel12 7mo agoHey, they did admit that they vibed this in a week and released it to everyone.
- pncnmnp 7mo agoOn a similar tangent, but on the opposite end of the spectrum, check out this month-old discussion on HN: https://news.ycombinator.com/item?id=46772003 https://news.ycombinator.com/item?id=46772003 ChatGPT's code execution container contains 56 vCPUs!! Back then, simonw mentioned: > It appears to have 4GB of RAM and 56 (!?) CPU cores https://chatgpt.com/share/6977e1f8-0f94-8006-9973-e9fab6d24418 https://chatgpt.com/share/6977e1f8-0f94-8006-9973-e9fab6d244... I'm seeing something similar on a free account too: https://chatgpt.com/share/69a5bbc8-7110-8005-8622-682d5943dcd9 https://chatgpt.com/share/69a5bbc8-7110-8005-8622-682d5943dc... On my paid account, I was able to verify this. I was also able to get a CPU-bound workload running on all cores. Interestingly, it was not able to fully saturate them, though - despite trying for 20-odd minutes. I asked it to test with stress-ng, but it looks like it had no outbound connectivity to install the tool: https://chatgpt.com/share/69a5c698-28bc-8005-96b6-9c089b0cc561 https://chatgpt.com/share/69a5c698-28bc-8005-96b6-9c089b0cc5... Anyways, that's a lot of compute. Not quite sure why its necessary for a plus account. Would love to get some thoughts on this?
- daemonk 7mo agoJust write a Claude OS already.
- wutwutwat 7mo agoAre we sure that this isn't a sparse image? It will report as the full size in finder, but it won't actually be consuming that much space if it's a sparse image
- aplomb1026 7mo ago[flagged]
- _orcaman_ 7mo agoA better UX would be to prompt the user, asking "Would you like to use the app in a sandbox for enhanced safety?" and only then download the Ubuntu linux image used in the VM
- sometimez 7mo agoSame thing on Windows. The VM bundle is at %AppData%\Claude\vm_bundles
- bichonnages 7mo agoIn the meantime, I deleted the virtual machine and the Claude application. I simply created a web app through Safari. It works very well.