Posts under App & System Services topic

Post

Replies

Boosts

Views

Activity

iOS 27: CPNowPlayingTemplate does not follow the active Now Playing client between an app's own client and its ApplicationMusicPlayer client (FB24840951)
On iOS 27, an app of mine that plays both its own audio and Apple Music tracks has two Now Playing clients in MediaRemote, as any app using ApplicationMusicPlayer.shared does: its own process's MPNowPlayingInfoCenter.default(), and MusicKit's player hosted out of process by com.apple.MediaPlayer.RemotePlayerService. MediaRemote elects between them correctly - the client whose process is making sound becomes active - and both the Lock Screen and the CarPlay dashboard follow the change. My CPNowPlayingTemplate does not. It stays on whichever client it was on when the change happened, so during an Apple Music track the car shows my own (now stale) entry with the clock frozen and a play glyph while music is audible; in some sessions the reverse, where my own audio after a track gets a blank template whose play presses are delivered to MusicKit's empty player and interrupt playback. From mediaremoted on iOS 27, handlePlaybackQueueRequest from CarPlayTemplateUIHost returns for (pid) > default throughout a track, and no contentItemChange for the RemotePlayerService path is ever posted to CarPlayTemplateUIHost, though it is posted to springboard, CarPlayApp and MediaRemoteUI. On iOS 26.6.1 with the same build, the same template host reads and commands RemotePlayerService/ during the track and > default afterwards. So the routing of commands to the active client is not what changed - what the template reads and sends to is. Filed as FB24840951 with mediaremoted captures from both OS versions, full sysdiagnose archives and screen recordings of the car screen beside the Lock Screen. Two questions: Is there a supported way for an audio app to tell CPNowPlayingTemplate which of its Now Playing clients to display? MPNowPlayingSession looks like the intended mechanism but accepts only AVPlayer instances, so it cannot represent either an AVAudioEngine graph or MusicKit's player; tested with a dormant AVPlayer it reported isActive == true every time and moved the template on some tracks and not others. Does the new MiniPlayer affect this? WWDC26's "Rev up your CarPlay app" says the MiniPlayer is new in iOS 27 and appears automatically for every app that shows now playing. Since the template was reworked in the same release this regressed in, does CPNowPlayingTemplate.shared.allowsMiniPlayer = false change which client is read? I have not tested it yet and will report back either way. Meanwhile the only thing that moves the car is republishing my own entry once a second as a new content item, which the template does re-read, so the clock steps instead of freezing. That ships in PodMelody 1.1.4, a workaround for an OS bug rather than a fix - and it doesn't resolve the mismatched play/pause glyph. If you have an audio app using ApplicationMusicPlayer and CarPlay, I would be glad to know whether you see the same thing, and in which car - duplicates on the Feedback are what get these prioritised.
0
0
149
1w
watchOS 27: Environmental Audio Exposure sampling became extremely sparse
After updating my Apple Watch Series 10 to the public release of watchOS 27, Environmental Sound Level measurements became extremely sparse. Before watchOS 27, with Environmental Sound Measurements enabled, my watch recorded environmental sound data approximately every 30 seconds and the coverage was nearly continuous throughout the day. After updating the same Apple Watch to watchOS 27, the behavior changed significantly: Environmental Sound Level samples are much less frequent Large gaps appear between measurements Overall daily temporal coverage is dramatically reduced The same change is visible both in the Health app and through HealthKit using HKQuantityTypeIdentifier.environmentalAudioExposure No relevant settings were changed, and Environmental Sound Measurements are still enabled. This is important for apps that use Environmental Audio Exposure data for time-based analysis. In my case, I use this data for sleep and nap environment analysis. With the much sparser sampling on watchOS 27, it is difficult to reliably evaluate the acoustic environment during a specific sleep period. I have also seen other watchOS 27 users reporting similar behavior: https://www.reddit.com/r/watchOSBeta/comments/1wjrdaq/watchos_27_broke_the_noise_monitoring_app/ I submitted a Feedback Assistant report: FB24837491 Has anyone else observed the same change on watchOS 27? I’m especially interested in whether this is: an intentional change to the sampling or aggregation strategy, a HealthKit write-frequency change, or a regression in watchOS 27. If anyone has compared HKQuantitySample.startDate, endDate, sample duration, and sample interval before and after the watchOS 27 update, that data would be very useful for comparison.
0
1
155
1w
Matter device shows “Uncertified Accessory” in Apple Home despite CSA certification and DCL listing (OEM/ODM, Portfolio Family CD)
Hello Apple Home/Matter team, our Matter product is CSA-certified, has a valid CD, and is listed in Compliance DCL. In testing with HomePod mini as border router, commissioning proceeds but Apple Home still shows “Uncertified Accessory.” We are an OEM/ODM manufacturer: product vendor_id/product_id belong to the brand owner, while dac_origin_vendor_id/dac_origin_product_id belong to us(manufacturer). The device also uses the brand owner’s product VID/PID at runtime. Our certification is Portfolio Family, so CD product_id is an array covering 6 SKUs. Is this model expected to pass Apple Home certification checks, and what are the most common causes of this warning? Emma
1
1
399
1w
IOConnectMapMemory questions
I am developing a dext that is running into issues pertaining to IOConnectMapMemory (at least I think so). There are 3 parts of code that are involved, the dext (which allocates the memory in the first place), a user client library which is involved in connecting to the dext and releasing when the hardware is removed, and finally some processing code (at the user level) which executes on this shared block of memory from the dext. The shared memory is allocated using an IOBufferMemoryDescriptor: IOBufferMemoryDescriptor::Create(kIOMemoryDirectionNone, sizeof(sharedMemoryBlock), IOVMPageSize, &(ivars->mSharedMemoryBlockMemDesc)); The User Client Library acquires a mapped pointer to this memory by calling IOConnectMapMemory: IOConnectMapMemory(mConnect, kMemoryType_SharedMemoryBlock, mach_task_self(), (mach_vm_address_t*)&mUserClientSharedBlockPtr, (mach_vm_size_t*)&mSizeOfUserClientSharedBlock, kIOMapAnywhere); …which triggers the dext’s IOUserClient subclass' “CopyClientMemoryForType_Impl”. That code adds a retain and returns a pointer to the IOBufferMemoryDescriptor: case kMemoryType_SharedMemoryBlock: // error checks first (make sure it’s allocated and initialized, etc) ivars->mSharedMemoryBlockMemDesc->retain(); *memory = ivars->mSharedMemoryBlockMemDesc; break; IOConnectMapMemory returns the “mapped pointer” (in mUserClientSharedBlockPtr) to the User Client Library, which in turn provides it to the processing code. The processing code checks the pointer validity, and if valid, runs its processing. This worked fine with a kext implementation. This fails with dext implementation, because during the processing call (after validity check but during usage) the mapped pointer can become NULL, which seems to be against the design pattern, and causes the application to crash due to an access violation (dereferencing NULL). I assume I am doing something incorrect here, but I’m not seeing what it is. The memory was retained, so it should not be deleted until the User Client Library has released it, but the only release available would be IOConnectUnmapMemory, and that fails with “invalid argument” (0xE00002C2) after the device is hot-unplugged. I am not finding IOConnectMapMemory examples on developer.apple.com. I have verified via the forums that IOConnectMapMemory is still a recommended practice with DriverKit development: https://developer.apple.com/forums/thread/803947?answerId=862249022#862249022 . What’s the trick here for stability? The device is a peripheral which can be unplugged or turned off at any time, which would result in the dext and user client library code tearing down the structures and memory, but it should be able to do so safely without causing access violations. (Note, this has been simplified for the purpose of focusing the question, in reality there are 4 separate memory blocks which are shared in this fashion: two ring buffers, main engine status, and client status. They each use their own memory_type definition, but a general solution is needed and can be applied to all 4, and there can be multiple clients at any point in time).
1
0
1.1k
1w
Network UPS?
I found some nice code that implements a NUT client, and now I want to take the next step -- I would like to get it to show up as a UPS for macOS. But I've never done anything with IOKit... and there don't seem to be a lot of examples of, maybe, IOPowerSources?
6
0
458
1w
Crashe__CFRunLoopServiceMachPort.cold 96% Foreground
Hello, we have encountered a large number of __CFRunLoopServiceMachPort.cold crashes on iOS 26. These crashes frequently occur when the app transitions from the background to the foreground or is launched after sitting idle for a period of time. Despite extensive analysis, we have been unable to find a solution. Currently, the crash data indicates that this issue is specific to iOS 26. We would greatly appreciate your assistance. Thank you very much! Hardware Model: iPhone18,1 OS Version: iPhone OS 26.5.2 (23F84) Release Type: User Baseband Version: 1.60.02 Crash Reporter Key: fda96a4036dcb83e124660e11b654c9484b81dae Incident Identifier: EF18C4DD-7624-42D0-BA72-F17BBC263B16 Time Awake Since Boot: 2900000 seconds Triggered by Thread: 0, Dispatch Queue: com.apple.main-thread Exception Type: EXC_BREAKPOINT (SIGTRAP) Exception Codes: 0x0000000000000001, 0x00000001917d316c Termination Reason: Namespace SIGNAL, Code 5, Trace/BPT trap: 5 Terminating Process: exc handler [82210] Application Specific Information: (ipc/rcv) invalid name Thread 0 name: Dispatch queue: com.apple.main-thread Thread 0 Crashed: 0 CoreFoundation 0x1917d316c __CFRunLoopServiceMachPort.cold.1 + 64 1 CoreFoundation 0x19168a444 __CFRunLoopServiceMachPort + 416 2 CoreFoundation 0x191654310 __CFRunLoopRun + 1188 3 CoreFoundation 0x19165354c _CFRunLoopRunSpecificWithOptions + 532 4 GraphicsServices 0x236df7498 GSEventRunModal + 120 5 UIKitCore 0x19734c244 -[UIApplication _run] + 796 6 UIKitCore 0x1972b7158 UIApplicationMain + 332 7 KMMVideo 0x1047fe24c 0x104304000 + 5218892 8 dyld 0x18e261c1c start + 6928 Thread 1 name: transmit_hls_7683_193735 Thread 1: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 libc++.1.dylib 0x1a0d5dbcc std::__1::condition_variable::wait(std::__1::unique_lockstd::__1::mutex&) + 32 3 iOSPlayer 0x118cd6114 a_task_runner::worker() + 116 4 iOSPlayer 0x118cd5650 a_task_runner::work_thread() + 196 5 iOSPlayer 0x118cd654c void* std::__1::__thread_proxy[abi:ne200100]<std::__1::tuple<std::__1::unique_ptr<std::__1::__thread_struct, std::__1::default_deletestd::__1::__thread_struct>, void (a_task_runner::)(), a_task_runner>>(void*) + 72 6 libsystem_pthread.dylib 0x1f0854438 _pthread_start + 136 7 libsystem_pthread.dylib 0x1f08508cc thread_start + 8 Thread 2: 0 libsystem_kernel.dylib 0x2407d9ed8 read + 8 1 XLTranscodeKit 0x115bb5f4c runtime.read_trampoline.abi0 + 28 Thread 3: Thread 4: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 XLTranscodeKit 0x115bb6648 runtime.pthread_cond_wait_trampoline.abi0 + 24 3 XLTranscodeKit 0x115bb4fb8 runtime.asmcgocall.abi0 + 200 4 ??? 0xd65f03c0 ??? Thread 5: 0 XLTranscodeKit 0x115b3eb68 */bytealg.IndexByteString + 40 1 XLTranscodeKit 0x115b966b8 runtime.findnull + 104 Thread 6: 0 libsystem_kernel.dylib 0x2407db8dc kevent + 8 1 XLTranscodeKit 0x115bb6398 runtime.kevent_trampoline.abi0 + 40 Thread 7: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 XLTranscodeKit 0x115bb6648 runtime.pthread_cond_wait_trampoline.abi0 + 24 3 XLTranscodeKit 0x115bb4fb8 runtime.asmcgocall.abi0 + 200 4 ??? 0xd65f03c0 ???
3
0
390
1w
Can an ExtensionFoundation-based extension on macOS have its own extension point and host its own extensions?
It is possible for an extension to an app (based on ExtensionFoundation) to declare its own extension point and host its own ExtensionFoundation extensions? Based on the documentation, I am guessing the answer is no, but worth double-checking. What would be the reason to prevent this? Every ExtensionFoundation extension runs in its own process, and may have need to be extended safely just as its host app does. Thank you!
3
0
215
1w
Removing stale Local Network entries?
Hello, I'm desperately looking for a way to purge the contents of the Local Network allowlist in System Settings. Every version of a test app I've ever used gets an entry in there, and apparently so does each build of Chrome and Claude Code. Claude recommended I include the following context, and if there's a specific answer to that, great, but any way of purging this list would make me very happy. ==== Caution: slop below this line ==== macOS 27.0 (26A428), Apple silicon. The Local Network list has 471 entries, many dead: Chrome code_sign_clone paths that no longer exist, old ad-hoc builds, uninstalled apps. The pane can't remove any. Is there a supported way to remove entries or reset the list, short of Recovery? Editing /Library/Preferences/com.apple.networkextension.plist as root fails with EPERM, both rename-over and open-for-write. New files in that directory work. SIP is on, the file has no flags or xattrs, Full Disk Access didn't help, and there are no Sandbox/TCC denials in the log. What protects this file?
3
0
454
1w
Custom Installer Plugin (x86_64 bundle) is not loaded on macOS 26A428 / 25G229 / 24H23, causing an installer GUI pane to be skipped
Summary A third-party PKG installer that ships a custom Installer Plugin no longer displays one of its selection panes. The plugin bundle appears not to be loaded, so the pane that it provides is silently skipped and the user cannot choose the intended installation option. This behavior started with recent macOS releases and did not occur on the immediately preceding versions, so it looks like a regression. Environment Machine: MacBook Pro 14-inch (M3) Affected builds: macOS 27.0 (26A428) macOS 26.7 (25G229) macOS 15.8 (24H23) Not affected: macOS 26.6 and earlier macOS 15.7 and earlier Reproducibility: every time Plugin binary: Mach-O 64-bit bundle, x86_64 only (no arm64 slice) Steps to Reproduce Download the Epson iProjection Ver.4.04 installer from the vendor support site: https://support.epson.net/setupnavi/?LG2=EN&OSC=MI&PINF=vpapp&MKN=EB-770Fi Mount the downloaded disk image and run the PKG installer. Step through the installer GUI and observe the pane transitions. Expected Result The installer GUI shows the "Application type" selection pane provided by the bundled Installer Plugin. Actual Result The "Application type" pane is never shown. The installer proceeds as if the plugin did not exist, and the user cannot select the installation type. What I Checked 1. The plugin is present inside the PKG pkgutil --expand-full PKG_PATH DEST_DIR The expanded payload contains the plugin bundle and its Mach-O executable under Contents/MacOS. 2. Architecture of the plugin binary file DEST_DIR/PluginName.bundle/Contents/MacOS/PluginName Result: Mach-O 64-bit bundle x86_64. It is a single-architecture binary with no arm64 slice. 3. The plugin is actually touched at install time sudo fs_usage -w -f filesys InstallerRemotePluginService-x86 opens the plugin executable inside the installer's temporary directory (a path under /private/tmp/com.apple.installer* ). So the plugin is reached as a load target, but the pane still does not appear. 4. Code signature validation When the installer is launched directly from the mounted disk image, code signature validation fails with: Too many levels of symbolic links My working theory is that the bundle contents are turned into symbolic links when the plugin is expanded, and that this causes codesign validation to fail, so the plugin is rejected before it can register its pane. 5. Code evaluation by syspolicyd log stream --info --debug --predicate 'process == "syspolicyd"' GK package assessment, GK process assessment and GK performScan entries are present, so Gatekeeper evaluation itself is running. The following also appears: Error Domain=NSOSStatusErrorDomain Code=-67062 Unsigned code in: PST: (path: REDACTED), (team: (null)), (id: (null)), (bundle_id: (null)) The PST path is anonymized in the log, so I could not confirm that this particular assessment refers to the plugin bundle. 6. XProtect evaluation results differ between versions log stream --info --debug --predicate 'process == "syspolicyd"' On the versions where the installer works correctly, the GK Xprotect results lines explicitly include a file URL pointing at the plugin bundle inside the installer temporary directory. On the affected builds, searching the same log for the plugin bundle name returns zero matches. That suggests the bundle is not being processed as an XProtect evaluation target at all on the newer builds. Question Was there a change in how Installer Plugins are expanded or validated in these releases, in particular around symlinked bundle contents or single-architecture x86_64 plugins? Any guidance on the supported way to ship an Installer Plugin so that it is still loaded on current macOS would be appreciated.
1
0
253
1w
Error Domain=PKPassKitErrorDomain Code=2
We are getting this error frequently and our customers are getting increasing frustrated when they are unable to add their credit card to Apple Wallet. There is no clear explanation on when this error arises. I sincerely request help to understand the cause of this issue. Device info: Apple iOS 26.6.1.
0
0
94
1w
In App Provisioning PKErrorHTTPResponseStatusCodeKey=500
Hello, we are developing in app provisioning of our American Express network cards. After clicking add to apple wallet in our app, I launch the PKAddPaymentPassViewController and click next. It loads for a few seconds and then I get: [<private>] ProvisioningOperationComposer: Step '<private>' failed with error Error Domain=PKProvisioningErrorDomain Code=5 UserInfo={PKErrorHTTPResponseStatusCodeKey=500} Does anyone have any insight on what this error means?
5
1
1.4k
1w
Family Controls authorization error
Hi everyone, I'm developing an iOS app that uses Apple's Family Controls / Screen Time APIs. I've encountered a strange issue when testing with multiple devices: The app works normally on the first device. When I install the same TestFlight build on a second device, the user completes the Family Controls authorization successfully. Immediately after authorization, an error appears: "Family Controls is only available for one application." After dismissing the error, the app still works normally. Screen Time / Shield functionality also appears to work as expected. The issue seems to occur specifically when authorizing the app on a second device. Has anyone encountered this error before?
0
0
75
1w
StoreKit External Purchases or Offers entitlement missing from macOS provisioning profile
Hey We are implementing EU external purchases for both our iOS and native macOS apps as it's written here: https://developer.apple.com/br/support/payment-options-on-the-app-store-in-the-eu For our App ID, we enabled StoreKit External Purchases or Offers, whose entitlement key is: com.apple.developer.storekit.custom-purchase-link.allowed-regions The capability works for iOS, but newly generated macOS provisioning profiles do not contain this entitlement. In Certificates, Identifiers & Profiles, the capability itself shows Platform Support: iOS, tvOS, watchOS, visionOS - macOS is not listed. However, the StoreKit documentation for ExternalPurchaseCustomLink and the EU alternative-payment documentation appear to describe external-purchase support more generally. Could you please clarify: Is com.apple.developer.storekit.custom-purchase-link.allowed-regions currently supported for native macOS apps distributed through the Mac App Store? If not, what entitlement and API should a native macOS app use for EU external purchases and external-purchase token reporting? Is macOS support for the StoreKit External Purchases or Offers entitlement planned or available through a separate entitlement request? At the moment, our macOS provisioning profiles cannot contain this entitlement because macOS is not listed as a supported platform for this capability. Thank you!
0
0
518
1w
[macOS 27] Non-sandboxed Developer ID app blocked from accessing Chrome and Firefox directories under ~/Library/Application Support/ — intentional TCC change?
Environment: App: Developer ID signed, non-sandboxed macOS app Browsers affected: Google Chrome, Mozilla Firefox Safari: Working fine on macOS 27 Working on: macOS 26 and earlier Broken on: macOS 27 (Golden Gate) Issue Our non-sandboxed, Developer ID signed macOS app interacts with Chrome and Firefox directories under ~/Library/Application Support/ as part of its browser extension deployment workflow. On macOS 26 and earlier, this worked without any special permissions. On macOS 27, the same operations are silently blocked — no TCC prompt is shown to the user, access is simply denied. Granting Full Disk Access to our app via System Settings > Privacy & Security > Full Disk Access resolves the issue completely on macOS 27. Safari is unaffected — our Safari extension is bundled directly inside our app and continues to work correctly on macOS 27 without any additional permissions. Question Has macOS 27 intentionally introduced TCC or MACL-based protection over Chrome and Firefox directories under ~/Library/Application Support/, blocking access from non-owner processes including non-sandboxed Developer ID apps? If this is an intentional change, is Full Disk Access the expected requirement going forward, or is there a more targeted entitlement or Apple-recommended approach for a non-sandboxed app that legitimately needs to access browser directories as part of an extension deployment workflow?
1
0
231
1w
On File System Permissions
Modern versions of macOS use a file system permission model that’s far more complex than the traditional BSD rwx model, and this post is my attempt at explaining that model. If you have a question about this, post it here on DevForums. Put your thread in the App & System Services > Core OS topic area and tag it with Files and Storage. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = "eskimo" + "1" + "@" + "apple.com" On File System Permissions Modern versions of macOS have five different file system permission mechanisms: Traditional BSD permissions Access control lists (ACLs) App Sandbox Mandatory access control (MAC) Endpoint Security (ES) The first two were introduced a long time ago and rarely trip folks up. The second two are newer, more complex, and specific to macOS, and thus are the source of some confusion. Finally, Endpoint Security allows third-party developers to deny file system operations based on their own criteria. This post offers explanations and advice about all of these mechanisms. Error Codes App Sandbox and the mandatory access control system are both implemented using macOS’s sandboxing infrastructure. When a file system operation fails, check the error to see whether it was blocked by this sandboxing infrastructure. If an operation was blocked by BSD permissions or ACLs, it fails with EACCES (Permission denied, 13). If it was blocked by something else, it’ll fail with EPERM (Operation not permitted, 1). If you’re using Foundation’s FileManager, these error are both reported as Foundation errors, for example, the NSFileReadNoPermissionError error. To recover the underlying error, get the NSUnderlyingErrorKey property from the info dictionary. App Sandbox File system access within the App Sandbox is controlled by two factors. The first is the entitlements on the main executable. There are three relevant groups of entitlements: The com.apple.security.app-sandbox entitlement enables the App Sandbox. This denies access to all file system locations except those on a built-in allowlist (things like /System) or within the app’s containers. The various “standard location” entitlements extend the sandbox to include their corresponding locations. The various “file access temporary exceptions” entitlements extend the sandbox to include the items listed in the entitlement. Collectively this is known as your static sandbox. The second factor is dynamic sandbox extensions. The system issues these extensions to your sandbox based on user behaviour. For example, if the user selects a file in the open panel, the system issues a sandbox extension to your process so that it can access that file. The type of extension is determined by the main executable’s entitlements: com.apple.security.files.user-selected.read-only results in an extension that grants read-only access. com.apple.security.files.user-selected.read-write results in an extension that grants read/write access. Note There’s currently no way to get a dynamic sandbox extension that grants executable access. For all the gory details, see this post. These dynamic sandbox extensions are tied to your process; they go away when your process terminates. To maintain persistent access to an item, use a security-scoped bookmark. See Accessing files from the macOS App Sandbox. To pass access between processes, use an implicit security scoped bookmark, that is, a bookmark that was created without an explicit security scope (no .withSecurityScope flag) and without disabling the implicit security scope (no .withoutImplicitSecurityScope flag)). If you have access to a directory — regardless of whether that’s via an entitlement or a dynamic sandbox extension — then, in general, you have access to all items in the hierarchy rooted at that directory. This does not overrule the MAC protection discussed below. For example, if the user grants you access to ~/Library, that does not give you access to ~/Library/Mail because the latter is protected by MAC. Finally, the discussion above is focused on a new sandbox, the thing you get when you launch a sandboxed app from the Finder. If a sandboxed process starts a child process, that child process inherits its sandbox from its parent. For information on what happens in that case, see the Note box in Enabling App Sandbox Inheritance. IMPORTANT The child process inherits its parent process’s sandbox regardless of whether it has the com.apple.security.inherit entitlement. That entitlement exists primarily to act as a marker for App Review. App Review requires that all main executables have the com.apple.security.app-sandbox entitlement, and that entitlements starts a new sandbox by default. Thus, any helper tool inside your app needs the com.apple.security.inherit entitlement to trigger inheritance. However, if you’re not shipping on the Mac App Store you can leave off both of these entitlement and the helper process will inherit its parent’s sandbox just fine. The same applies if you run a built-in executable, like /bin/sh, as a child process. When the App Sandbox blocks something, it might generates a sandbox violation report. For information on how to view these reports, see Discovering and diagnosing App Sandbox violations. To learn more about the App Sandbox, see the various links in App Sandbox Resources. For information about how to embed a helper tool in a sandboxed app, see Embedding a Command-Line Tool in a Sandboxed App. Mandatory Access Control Mandatory access control (MAC) has been a feature of macOS for many releases, but it’s become a lot more prominent since macOS 10.14. There are many flavours of MAC but the ones you’re most likely to encounter are: Full Disk Access (macOS 10.14 and later) Files and Folders (macOS 10.15 and later) App bundle protection (macOS 13 and later) App container protection (macOS 14 and later) App group container protection (macOS 15 and later) Data Vaults (see below) and other internal techniques used by various macOS subsystems The exact list of file system locations protected by MAC is not documented and, as illustrated by the list above, can change over time. If your process runs into a MAC check the system might prompt the user to grant the process access, or it might just fail the access. If the user grants the process access, the system might only grant that access for this specific process, or it might persist that access for the program that this process is running. The exact behaviour varies based on the specific location in the file system and can also vary between different versions of macOS. Mandatory access control, as the name suggests, is mandatory; it’s not an opt-in like the App Sandbox. Rather, all processes on the system, including those running as root, as subject to MAC. Data Vaults are not a third-party developer opportunity. See this post if you’re curious. In the Full Disk Access and Files and Folders cases, users grant a program a MAC privilege using System Settings > Privacy & Security. Some MAC privileges are per user (Files and Folders) and some are system wide (Full Disk Access). If you’re not sure, run this simple test: On a Mac with two users, log in as user A and enable the MAC privilege for a program. Now log in as user B. Does the program have the privilege? If a process tries to access an item restricted by MAC, the system may prompt the user to grant it access there and then. For example, if an app tries to access the desktop, you’ll see an alert like this: “AAA” would like to access files in your Desktop folder. [Don’t Allow] [OK] To customise this message, set Files and Folders properties in your Info.plist. This system only displays this alert once. It remembers the user’s initial choice and returns the same result thereafter. This relies on your code having a stable code signing identity. If your code is unsigned, or signed ad hoc (Signed to Run Locally in Xcode parlance), the system can’t tell that version N+1 of your code is the same as version N, and thus you’ll encounter excessive prompts. Note For information about how that works, see TN3127 Inside Code Signing: Requirements. The Files and Folders prompts only show up if the process is running in a GUI login session. If not, the operation is allowed or denied based on existing information. If there’s no existing information, the operation is denied by default. For more information about app and app group container protection, see the links in Trusted Execution Resources. For more information about app groups in general, see App Groups: macOS vs iOS: Working Towards Harmony On managed systems the site admin can use the com.apple.TCC.configuration-profile-policy payload to assign MAC privileges. For testing purposes you can reset parts of TCC using the tccutil command-line tool. For general information about that tool, see its man page. For a list of TCC service names, see the posts on this thread. Note TCC stands for transparency, consent, and control. It’s the subsystem within macOS that manages most of the privileges visible in System Settings > Privacy & Security. TCC has no API surface, but you see its name in various places, including the above-mentioned configuration profile payload and command-line tool, and the name of its accompanying daemon, tccd. While tccutil is an easy way to do basic TCC testing, the most reliable way to test TCC is in a VM, restoring to a fresh snapshot between each test. If you want to try this out, crib ideas from Testing a Notarised Product. The MAC privilege mechanism is heavily dependent on the concept of responsible code. For example, if an app contains a helper tool and the helper tool triggers a MAC prompt, we want: The app’s name and usage description to appear in the alert. The user’s decision to be recorded for the whole app, not that specific helper tool. That decision to show up in System Settings under the app’s name. For this to work the system must be able to tell that the app is the responsible code for the helper tool. The system has various heuristics to determine this and it works reasonably well in most cases. However, it’s possible to break this link. I haven’t fully research this but my experience is that this most often breaks when the child process does something ‘odd’ to break the link, such as trying to daemonise itself. If you’re building a launchd daemon or agent and you find that it’s not correctly attributed to your app, add the AssociatedBundleIdentifiers property to your launchd property list. See the launchd.plist man page for the details. Scripting MAC presents some serious challenges for scripting because scripts are run by interpreters and the system can’t distinguish file system operations done by the interpreter from those done by the script. For example, if you have a script that needs to manipulate files on your desktop, you wouldn’t want to give the interpreter that privilege because then any script could do that. The easiest solution to this problem is to package your script as a standalone program that MAC can use for its tracking. This may be easy or hard depending on the specific scripting environment. For example, AppleScript makes it easy to export a script as a signed app, but that’s not true for shell scripts. TCC and Main Executables TCC expects its bundled clients — apps, app extensions, and so on — to use a native main executable. That is, it expects the CFBundleExecutable property to be the name of a Mach-O executable. If your product uses a script as its main executable, you’re likely to encounter TCC problems. To resolve these, switch to using a Mach-O executable. For an example of how you might do that, see this post. Endpoint Security Endpoint Security (ES) is a general mechanism for third-party products to enforce custom security policies on the Mac. An ES client asks ES to send it events when specific security-relevant operations occur. These events can be notifications or authorisations. In the case of authorisation events, the ES client must either allow or deny the operation. As you might imagine, the set of security-relevant operations includes file system operations. For example, when you open a file using the open system call, ES delivers the ES_EVENT_TYPE_AUTH_OPEN event to any interested ES clients. If one of those ES client denies the operation, the open system call fails with EPERM. For more information about ES, see the Endpoint Security framework documentation. Originally ES clients operated system wide. macOS 27 introduced a new mechanism, es_new_descendants_client, that allows an ES client to operate on the process hierarchy rooted at the client itself. Revision History 2026-09-18 Extended the Endpoint Security section to discuss es_new_descendants_client. Clarified the scope of MAC. 2025-11-04 Added a discussion of Endpoint Security. Made numerous minor editorial changes. 2024-11-08 Added info about app group container protection. Clarified that Data Vaults are just one example of the techniques used internally by macOS. Made other editorial changes. 2023-06-13 Replaced two obsolete links with links to shiny new official documentation: Accessing files from the macOS App Sandbox and Discovering and diagnosing App Sandbox violations. Added a short discussion of app container protection and a link to WWDC 2023 Session 10053 What’s new in privacy. 2023-04-07 Added a link to my post about executable permissions. Fixed a broken link. 2023-02-10 In TCC and Main Executables, added a link to my native trampoline code. Introduced the concept of an implicit security scoped bookmark. Introduced AssociatedBundleIdentifiers. Made other minor editorial changes. 2022-04-26 Added an explanation of the TCC initialism. Added a link to Viewing Sandbox Violation Reports.  Added the TCC and Main Executables section. Made significant editorial changes. 2022-01-10 Added a discussion of the file system hierarchy. 2021-04-26 First posted.
0
0
14k
1w
CarPlay Driving Task notification press handling
We're trying to add simple notifications to our CarPlay integration that should open certain template when pressed, but the issue is that when pressing this notification on CarPlay screen nothing is invoked in the code (presumably didReceive should be invoked). All works fine with the same notification but pressed on the iPhone screen - didReceive is invoked properly. How should I handle the action when push notification is pressed on CarPlay screen?
1
0
409
1w
Is suspended spawn + audit_token_t matching a supported security boundary for one exact macOS process occurrence?
I’m designing a macOS privileged-service boundary and I’d like to clarify whether a process-occurrence authentication pattern previously described by Apple DTS is a supported shipping security contract, rather than just behaviour that happens to work on current macOS. Target: current macOS 26.x, using public APIs only. Threat model An arbitrary hostile process may run as the same ordinary, non-admin login user as the application. The attacker can launch an exact second copy of the legitimately signed requester binary. The attacker cannot obtain administrator / Touch ID authorization and does not control root, SIP, Recovery, the kernel, or the code-signing infrastructure. Desired property After a fresh Human-authorized operation, a root LaunchDaemon should grant authority to one specific requester process occurrence, not to every process having the same code-signing identity. Apple DTS thread 842442 describes a pattern based on: launching the requester suspended with posix_spawn(..., POSIX_SPAWN_START_SUSPENDED); obtaining a name/task port for that process; reading its TASK_AUDIT_TOKEN; resuming the process; and accepting only Mach messages whose kernel audit trailer identifies that same process occurrence. Thread 842442 also describes this area as being on “thin compatibility ice”, which is why I do not want to build a security boundary on behaviour that Apple does not intend applications to rely on. My core question is: Can a shipping macOS application rely on a pre-bound audit_token_t obtained from a suspended child and compare it against the audit token in subsequent raw Mach message trailers as a supported security boundary for that exact process occurrence? In particular, I need to know whether the supported contract covers: distinguishing another process with the exact same signed executable; PID reuse after the original process exits; messages queued before or around sender termination; a Mach send right transferred to another process — does the receiver see the audit token of the process that actually sends each message?; later exec by the original process; and whether full audit_token_t equality is an appropriate supported comparison for this purpose. If that is not a supported shipping contract, is there a current public XPC API that provides the equivalent property: binding one privileged-service session to one exact process occurrence rather than merely to its code-signing identity? I’m specifically trying to distinguish: code identity = this is an approved executable from mission authority = this one particular authorized process occurrence I’m happy with a negative answer if macOS does not expose a stable public contract for the latter. Related Apple DTS discussion: https://developer.apple.com/forums/thread/842442
11
0
652
1w
Endpoint Security: preventing exec after the ES client disconnects or exits
I'm evaluating Endpoint Security for a supervised macOS worker and a separate evidence collector. This is a question about supported API guarantees; I don't have a reproduced macOS bug. Before collection starts, I need to identify the worker's successful initial executable image. That image must remain current until every collector read and its resulting copy or storage operation has finished, including operations that ultimately report failure. Here, "remain current" means preventing replacement by a later successful exec, not preventing ordinary memory changes within the running program. The proposed policy would authorize the initial exec, then deny subsequent ES_EVENT_TYPE_AUTH_EXEC requests for that worker while collection is active. This is a design under consideration, not an implemented or tested guard. The unresolved case is loss of the ES client while a collector operation is already in flight. If the client crashes, is deleted, or disconnects: What happens to an exec authorization request already pending at that point? What governs later exec attempts after the client is gone? Can a supported mechanism keep exec replacement blocked until the collector's in-flight operations finish, while allowing shutdown within a finite bound? A later health check would not cover an interval in which replacement was already allowed. I reviewed Apple's WWDC20 Endpoint Security session, but haven't established a documented client-loss guarantee for this requirement. I'm asking about client loss separately from an authorization-response deadline expiring. Please point me to the applicable public API contract, including macOS/SDK availability and entitlement requirements. If Endpoint Security cannot provide this guarantee, that limitation would help me reconsider the design. Any supported ordering requirement for establishing the initial successful exec before the first collector read would also be useful.
6
0
1.1k
1w
StoreKit returns 0 products for 6 valid subscriptions in TestFlight
I am troubleshooting a reproducible StoreKit product discovery issue in a TestFlight build of my iOS application. App: Bundle ID: com.aileguvende.app Version: 2.9.59 Build: 97 On a physical iPhone using the TestFlight build, opening the subscription/paywall screen reproduces the issue. StoreKit availability is true and canMakePayments is true, but Product.products(for:) requests six auto-renewable subscription identifiers and returns: Requested products: 6 Returned products: 0 Not found products: 6 The query reports product_query_error with the plugin error code storekit_no_response. No purchase or Restore operation is required to reproduce the issue. The applicable TN3186 checks completed successfully: the App ID is explicit, In-App Purchase capability is enabled, the bundle ID and signing profile match, all six product identifiers match App Store Connect, all six products are available in Türkiye, pricing is configured, Turkish and English localizations are present, and the Paid Apps Agreement, banking, and tax information are active. The Apple Account and storefront are Türkiye. During the same runtime window, storekitd and appstored activity was observed and AMSErrorDomain activity was present, but no reliable native numeric error code or native product counts were exposed. CLIENT_PLUGIN_DEFECT_PROVEN=NO OFFICIAL_APPLE_INCIDENT_CONFIRMED=NO Feedback Assistant report: FB24793792. Could Apple engineers please verify: Whether the six subscriptions are present in the TestFlight/Sandbox commerce catalog for com.aileguvende.app. Whether the app-to-subscription catalog association is healthy on Apple’s backend. Whether there is a current StoreKit/App Store Commerce product-discovery issue where Product.products(for:) returns an empty result despite TN3186 checks passing. Whether any additional diagnostic is needed for FB24793792. This issue is reproducible without a transaction. I am not requesting a source-code change or a new build.
1
0
117
1w
iOS 27: CPNowPlayingTemplate does not follow the active Now Playing client between an app's own client and its ApplicationMusicPlayer client (FB24840951)
On iOS 27, an app of mine that plays both its own audio and Apple Music tracks has two Now Playing clients in MediaRemote, as any app using ApplicationMusicPlayer.shared does: its own process's MPNowPlayingInfoCenter.default(), and MusicKit's player hosted out of process by com.apple.MediaPlayer.RemotePlayerService. MediaRemote elects between them correctly - the client whose process is making sound becomes active - and both the Lock Screen and the CarPlay dashboard follow the change. My CPNowPlayingTemplate does not. It stays on whichever client it was on when the change happened, so during an Apple Music track the car shows my own (now stale) entry with the clock frozen and a play glyph while music is audible; in some sessions the reverse, where my own audio after a track gets a blank template whose play presses are delivered to MusicKit's empty player and interrupt playback. From mediaremoted on iOS 27, handlePlaybackQueueRequest from CarPlayTemplateUIHost returns for (pid) > default throughout a track, and no contentItemChange for the RemotePlayerService path is ever posted to CarPlayTemplateUIHost, though it is posted to springboard, CarPlayApp and MediaRemoteUI. On iOS 26.6.1 with the same build, the same template host reads and commands RemotePlayerService/ during the track and > default afterwards. So the routing of commands to the active client is not what changed - what the template reads and sends to is. Filed as FB24840951 with mediaremoted captures from both OS versions, full sysdiagnose archives and screen recordings of the car screen beside the Lock Screen. Two questions: Is there a supported way for an audio app to tell CPNowPlayingTemplate which of its Now Playing clients to display? MPNowPlayingSession looks like the intended mechanism but accepts only AVPlayer instances, so it cannot represent either an AVAudioEngine graph or MusicKit's player; tested with a dormant AVPlayer it reported isActive == true every time and moved the template on some tracks and not others. Does the new MiniPlayer affect this? WWDC26's "Rev up your CarPlay app" says the MiniPlayer is new in iOS 27 and appears automatically for every app that shows now playing. Since the template was reworked in the same release this regressed in, does CPNowPlayingTemplate.shared.allowsMiniPlayer = false change which client is read? I have not tested it yet and will report back either way. Meanwhile the only thing that moves the car is republishing my own entry once a second as a new content item, which the template does re-read, so the clock steps instead of freezing. That ships in PodMelody 1.1.4, a workaround for an OS bug rather than a fix - and it doesn't resolve the mismatched play/pause glyph. If you have an audio app using ApplicationMusicPlayer and CarPlay, I would be glad to know whether you see the same thing, and in which car - duplicates on the Feedback are what get these prioritised.
Replies
0
Boosts
0
Views
149
Activity
1w
watchOS 27: Environmental Audio Exposure sampling became extremely sparse
After updating my Apple Watch Series 10 to the public release of watchOS 27, Environmental Sound Level measurements became extremely sparse. Before watchOS 27, with Environmental Sound Measurements enabled, my watch recorded environmental sound data approximately every 30 seconds and the coverage was nearly continuous throughout the day. After updating the same Apple Watch to watchOS 27, the behavior changed significantly: Environmental Sound Level samples are much less frequent Large gaps appear between measurements Overall daily temporal coverage is dramatically reduced The same change is visible both in the Health app and through HealthKit using HKQuantityTypeIdentifier.environmentalAudioExposure No relevant settings were changed, and Environmental Sound Measurements are still enabled. This is important for apps that use Environmental Audio Exposure data for time-based analysis. In my case, I use this data for sleep and nap environment analysis. With the much sparser sampling on watchOS 27, it is difficult to reliably evaluate the acoustic environment during a specific sleep period. I have also seen other watchOS 27 users reporting similar behavior: https://www.reddit.com/r/watchOSBeta/comments/1wjrdaq/watchos_27_broke_the_noise_monitoring_app/ I submitted a Feedback Assistant report: FB24837491 Has anyone else observed the same change on watchOS 27? I’m especially interested in whether this is: an intentional change to the sampling or aggregation strategy, a HealthKit write-frequency change, or a regression in watchOS 27. If anyone has compared HKQuantitySample.startDate, endDate, sample duration, and sample interval before and after the watchOS 27 update, that data would be very useful for comparison.
Replies
0
Boosts
1
Views
155
Activity
1w
Matter device shows “Uncertified Accessory” in Apple Home despite CSA certification and DCL listing (OEM/ODM, Portfolio Family CD)
Hello Apple Home/Matter team, our Matter product is CSA-certified, has a valid CD, and is listed in Compliance DCL. In testing with HomePod mini as border router, commissioning proceeds but Apple Home still shows “Uncertified Accessory.” We are an OEM/ODM manufacturer: product vendor_id/product_id belong to the brand owner, while dac_origin_vendor_id/dac_origin_product_id belong to us(manufacturer). The device also uses the brand owner’s product VID/PID at runtime. Our certification is Portfolio Family, so CD product_id is an array covering 6 SKUs. Is this model expected to pass Apple Home certification checks, and what are the most common causes of this warning? Emma
Replies
1
Boosts
1
Views
399
Activity
1w
IOConnectMapMemory questions
I am developing a dext that is running into issues pertaining to IOConnectMapMemory (at least I think so). There are 3 parts of code that are involved, the dext (which allocates the memory in the first place), a user client library which is involved in connecting to the dext and releasing when the hardware is removed, and finally some processing code (at the user level) which executes on this shared block of memory from the dext. The shared memory is allocated using an IOBufferMemoryDescriptor: IOBufferMemoryDescriptor::Create(kIOMemoryDirectionNone, sizeof(sharedMemoryBlock), IOVMPageSize, &(ivars->mSharedMemoryBlockMemDesc)); The User Client Library acquires a mapped pointer to this memory by calling IOConnectMapMemory: IOConnectMapMemory(mConnect, kMemoryType_SharedMemoryBlock, mach_task_self(), (mach_vm_address_t*)&mUserClientSharedBlockPtr, (mach_vm_size_t*)&mSizeOfUserClientSharedBlock, kIOMapAnywhere); …which triggers the dext’s IOUserClient subclass' “CopyClientMemoryForType_Impl”. That code adds a retain and returns a pointer to the IOBufferMemoryDescriptor: case kMemoryType_SharedMemoryBlock: // error checks first (make sure it’s allocated and initialized, etc) ivars->mSharedMemoryBlockMemDesc->retain(); *memory = ivars->mSharedMemoryBlockMemDesc; break; IOConnectMapMemory returns the “mapped pointer” (in mUserClientSharedBlockPtr) to the User Client Library, which in turn provides it to the processing code. The processing code checks the pointer validity, and if valid, runs its processing. This worked fine with a kext implementation. This fails with dext implementation, because during the processing call (after validity check but during usage) the mapped pointer can become NULL, which seems to be against the design pattern, and causes the application to crash due to an access violation (dereferencing NULL). I assume I am doing something incorrect here, but I’m not seeing what it is. The memory was retained, so it should not be deleted until the User Client Library has released it, but the only release available would be IOConnectUnmapMemory, and that fails with “invalid argument” (0xE00002C2) after the device is hot-unplugged. I am not finding IOConnectMapMemory examples on developer.apple.com. I have verified via the forums that IOConnectMapMemory is still a recommended practice with DriverKit development: https://developer.apple.com/forums/thread/803947?answerId=862249022#862249022 . What’s the trick here for stability? The device is a peripheral which can be unplugged or turned off at any time, which would result in the dext and user client library code tearing down the structures and memory, but it should be able to do so safely without causing access violations. (Note, this has been simplified for the purpose of focusing the question, in reality there are 4 separate memory blocks which are shared in this fashion: two ring buffers, main engine status, and client status. They each use their own memory_type definition, but a general solution is needed and can be applied to all 4, and there can be multiple clients at any point in time).
Replies
1
Boosts
0
Views
1.1k
Activity
1w
Network UPS?
I found some nice code that implements a NUT client, and now I want to take the next step -- I would like to get it to show up as a UPS for macOS. But I've never done anything with IOKit... and there don't seem to be a lot of examples of, maybe, IOPowerSources?
Replies
6
Boosts
0
Views
458
Activity
1w
Crashe__CFRunLoopServiceMachPort.cold 96% Foreground
Hello, we have encountered a large number of __CFRunLoopServiceMachPort.cold crashes on iOS 26. These crashes frequently occur when the app transitions from the background to the foreground or is launched after sitting idle for a period of time. Despite extensive analysis, we have been unable to find a solution. Currently, the crash data indicates that this issue is specific to iOS 26. We would greatly appreciate your assistance. Thank you very much! Hardware Model: iPhone18,1 OS Version: iPhone OS 26.5.2 (23F84) Release Type: User Baseband Version: 1.60.02 Crash Reporter Key: fda96a4036dcb83e124660e11b654c9484b81dae Incident Identifier: EF18C4DD-7624-42D0-BA72-F17BBC263B16 Time Awake Since Boot: 2900000 seconds Triggered by Thread: 0, Dispatch Queue: com.apple.main-thread Exception Type: EXC_BREAKPOINT (SIGTRAP) Exception Codes: 0x0000000000000001, 0x00000001917d316c Termination Reason: Namespace SIGNAL, Code 5, Trace/BPT trap: 5 Terminating Process: exc handler [82210] Application Specific Information: (ipc/rcv) invalid name Thread 0 name: Dispatch queue: com.apple.main-thread Thread 0 Crashed: 0 CoreFoundation 0x1917d316c __CFRunLoopServiceMachPort.cold.1 + 64 1 CoreFoundation 0x19168a444 __CFRunLoopServiceMachPort + 416 2 CoreFoundation 0x191654310 __CFRunLoopRun + 1188 3 CoreFoundation 0x19165354c _CFRunLoopRunSpecificWithOptions + 532 4 GraphicsServices 0x236df7498 GSEventRunModal + 120 5 UIKitCore 0x19734c244 -[UIApplication _run] + 796 6 UIKitCore 0x1972b7158 UIApplicationMain + 332 7 KMMVideo 0x1047fe24c 0x104304000 + 5218892 8 dyld 0x18e261c1c start + 6928 Thread 1 name: transmit_hls_7683_193735 Thread 1: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 libc++.1.dylib 0x1a0d5dbcc std::__1::condition_variable::wait(std::__1::unique_lockstd::__1::mutex&) + 32 3 iOSPlayer 0x118cd6114 a_task_runner::worker() + 116 4 iOSPlayer 0x118cd5650 a_task_runner::work_thread() + 196 5 iOSPlayer 0x118cd654c void* std::__1::__thread_proxy[abi:ne200100]<std::__1::tuple<std::__1::unique_ptr<std::__1::__thread_struct, std::__1::default_deletestd::__1::__thread_struct>, void (a_task_runner::)(), a_task_runner>>(void*) + 72 6 libsystem_pthread.dylib 0x1f0854438 _pthread_start + 136 7 libsystem_pthread.dylib 0x1f08508cc thread_start + 8 Thread 2: 0 libsystem_kernel.dylib 0x2407d9ed8 read + 8 1 XLTranscodeKit 0x115bb5f4c runtime.read_trampoline.abi0 + 28 Thread 3: Thread 4: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 XLTranscodeKit 0x115bb6648 runtime.pthread_cond_wait_trampoline.abi0 + 24 3 XLTranscodeKit 0x115bb4fb8 runtime.asmcgocall.abi0 + 200 4 ??? 0xd65f03c0 ??? Thread 5: 0 XLTranscodeKit 0x115b3eb68 */bytealg.IndexByteString + 40 1 XLTranscodeKit 0x115b966b8 runtime.findnull + 104 Thread 6: 0 libsystem_kernel.dylib 0x2407db8dc kevent + 8 1 XLTranscodeKit 0x115bb6398 runtime.kevent_trampoline.abi0 + 40 Thread 7: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 XLTranscodeKit 0x115bb6648 runtime.pthread_cond_wait_trampoline.abi0 + 24 3 XLTranscodeKit 0x115bb4fb8 runtime.asmcgocall.abi0 + 200 4 ??? 0xd65f03c0 ???
Replies
3
Boosts
0
Views
390
Activity
1w
Can an ExtensionFoundation-based extension on macOS have its own extension point and host its own extensions?
It is possible for an extension to an app (based on ExtensionFoundation) to declare its own extension point and host its own ExtensionFoundation extensions? Based on the documentation, I am guessing the answer is no, but worth double-checking. What would be the reason to prevent this? Every ExtensionFoundation extension runs in its own process, and may have need to be extended safely just as its host app does. Thank you!
Replies
3
Boosts
0
Views
215
Activity
1w
Removing stale Local Network entries?
Hello, I'm desperately looking for a way to purge the contents of the Local Network allowlist in System Settings. Every version of a test app I've ever used gets an entry in there, and apparently so does each build of Chrome and Claude Code. Claude recommended I include the following context, and if there's a specific answer to that, great, but any way of purging this list would make me very happy. ==== Caution: slop below this line ==== macOS 27.0 (26A428), Apple silicon. The Local Network list has 471 entries, many dead: Chrome code_sign_clone paths that no longer exist, old ad-hoc builds, uninstalled apps. The pane can't remove any. Is there a supported way to remove entries or reset the list, short of Recovery? Editing /Library/Preferences/com.apple.networkextension.plist as root fails with EPERM, both rename-over and open-for-write. New files in that directory work. SIP is on, the file has no flags or xattrs, Full Disk Access didn't help, and there are no Sandbox/TCC denials in the log. What protects this file?
Replies
3
Boosts
0
Views
454
Activity
1w
Custom Installer Plugin (x86_64 bundle) is not loaded on macOS 26A428 / 25G229 / 24H23, causing an installer GUI pane to be skipped
Summary A third-party PKG installer that ships a custom Installer Plugin no longer displays one of its selection panes. The plugin bundle appears not to be loaded, so the pane that it provides is silently skipped and the user cannot choose the intended installation option. This behavior started with recent macOS releases and did not occur on the immediately preceding versions, so it looks like a regression. Environment Machine: MacBook Pro 14-inch (M3) Affected builds: macOS 27.0 (26A428) macOS 26.7 (25G229) macOS 15.8 (24H23) Not affected: macOS 26.6 and earlier macOS 15.7 and earlier Reproducibility: every time Plugin binary: Mach-O 64-bit bundle, x86_64 only (no arm64 slice) Steps to Reproduce Download the Epson iProjection Ver.4.04 installer from the vendor support site: https://support.epson.net/setupnavi/?LG2=EN&OSC=MI&PINF=vpapp&MKN=EB-770Fi Mount the downloaded disk image and run the PKG installer. Step through the installer GUI and observe the pane transitions. Expected Result The installer GUI shows the "Application type" selection pane provided by the bundled Installer Plugin. Actual Result The "Application type" pane is never shown. The installer proceeds as if the plugin did not exist, and the user cannot select the installation type. What I Checked 1. The plugin is present inside the PKG pkgutil --expand-full PKG_PATH DEST_DIR The expanded payload contains the plugin bundle and its Mach-O executable under Contents/MacOS. 2. Architecture of the plugin binary file DEST_DIR/PluginName.bundle/Contents/MacOS/PluginName Result: Mach-O 64-bit bundle x86_64. It is a single-architecture binary with no arm64 slice. 3. The plugin is actually touched at install time sudo fs_usage -w -f filesys InstallerRemotePluginService-x86 opens the plugin executable inside the installer's temporary directory (a path under /private/tmp/com.apple.installer* ). So the plugin is reached as a load target, but the pane still does not appear. 4. Code signature validation When the installer is launched directly from the mounted disk image, code signature validation fails with: Too many levels of symbolic links My working theory is that the bundle contents are turned into symbolic links when the plugin is expanded, and that this causes codesign validation to fail, so the plugin is rejected before it can register its pane. 5. Code evaluation by syspolicyd log stream --info --debug --predicate 'process == "syspolicyd"' GK package assessment, GK process assessment and GK performScan entries are present, so Gatekeeper evaluation itself is running. The following also appears: Error Domain=NSOSStatusErrorDomain Code=-67062 Unsigned code in: PST: (path: REDACTED), (team: (null)), (id: (null)), (bundle_id: (null)) The PST path is anonymized in the log, so I could not confirm that this particular assessment refers to the plugin bundle. 6. XProtect evaluation results differ between versions log stream --info --debug --predicate 'process == "syspolicyd"' On the versions where the installer works correctly, the GK Xprotect results lines explicitly include a file URL pointing at the plugin bundle inside the installer temporary directory. On the affected builds, searching the same log for the plugin bundle name returns zero matches. That suggests the bundle is not being processed as an XProtect evaluation target at all on the newer builds. Question Was there a change in how Installer Plugins are expanded or validated in these releases, in particular around symlinked bundle contents or single-architecture x86_64 plugins? Any guidance on the supported way to ship an Installer Plugin so that it is still loaded on current macOS would be appreciated.
Replies
1
Boosts
0
Views
253
Activity
1w
Error Domain=PKPassKitErrorDomain Code=2
We are getting this error frequently and our customers are getting increasing frustrated when they are unable to add their credit card to Apple Wallet. There is no clear explanation on when this error arises. I sincerely request help to understand the cause of this issue. Device info: Apple iOS 26.6.1.
Replies
0
Boosts
0
Views
94
Activity
1w
In App Provisioning PKErrorHTTPResponseStatusCodeKey=500
Hello, we are developing in app provisioning of our American Express network cards. After clicking add to apple wallet in our app, I launch the PKAddPaymentPassViewController and click next. It loads for a few seconds and then I get: [<private>] ProvisioningOperationComposer: Step '<private>' failed with error Error Domain=PKProvisioningErrorDomain Code=5 UserInfo={PKErrorHTTPResponseStatusCodeKey=500} Does anyone have any insight on what this error means?
Replies
5
Boosts
1
Views
1.4k
Activity
1w
Family Controls authorization error
Hi everyone, I'm developing an iOS app that uses Apple's Family Controls / Screen Time APIs. I've encountered a strange issue when testing with multiple devices: The app works normally on the first device. When I install the same TestFlight build on a second device, the user completes the Family Controls authorization successfully. Immediately after authorization, an error appears: "Family Controls is only available for one application." After dismissing the error, the app still works normally. Screen Time / Shield functionality also appears to work as expected. The issue seems to occur specifically when authorizing the app on a second device. Has anyone encountered this error before?
Replies
0
Boosts
0
Views
75
Activity
1w
StoreKit External Purchases or Offers entitlement missing from macOS provisioning profile
Hey We are implementing EU external purchases for both our iOS and native macOS apps as it's written here: https://developer.apple.com/br/support/payment-options-on-the-app-store-in-the-eu For our App ID, we enabled StoreKit External Purchases or Offers, whose entitlement key is: com.apple.developer.storekit.custom-purchase-link.allowed-regions The capability works for iOS, but newly generated macOS provisioning profiles do not contain this entitlement. In Certificates, Identifiers & Profiles, the capability itself shows Platform Support: iOS, tvOS, watchOS, visionOS - macOS is not listed. However, the StoreKit documentation for ExternalPurchaseCustomLink and the EU alternative-payment documentation appear to describe external-purchase support more generally. Could you please clarify: Is com.apple.developer.storekit.custom-purchase-link.allowed-regions currently supported for native macOS apps distributed through the Mac App Store? If not, what entitlement and API should a native macOS app use for EU external purchases and external-purchase token reporting? Is macOS support for the StoreKit External Purchases or Offers entitlement planned or available through a separate entitlement request? At the moment, our macOS provisioning profiles cannot contain this entitlement because macOS is not listed as a supported platform for this capability. Thank you!
Replies
0
Boosts
0
Views
518
Activity
1w
[macOS 27] Non-sandboxed Developer ID app blocked from accessing Chrome and Firefox directories under ~/Library/Application Support/ — intentional TCC change?
Environment: App: Developer ID signed, non-sandboxed macOS app Browsers affected: Google Chrome, Mozilla Firefox Safari: Working fine on macOS 27 Working on: macOS 26 and earlier Broken on: macOS 27 (Golden Gate) Issue Our non-sandboxed, Developer ID signed macOS app interacts with Chrome and Firefox directories under ~/Library/Application Support/ as part of its browser extension deployment workflow. On macOS 26 and earlier, this worked without any special permissions. On macOS 27, the same operations are silently blocked — no TCC prompt is shown to the user, access is simply denied. Granting Full Disk Access to our app via System Settings > Privacy & Security > Full Disk Access resolves the issue completely on macOS 27. Safari is unaffected — our Safari extension is bundled directly inside our app and continues to work correctly on macOS 27 without any additional permissions. Question Has macOS 27 intentionally introduced TCC or MACL-based protection over Chrome and Firefox directories under ~/Library/Application Support/, blocking access from non-owner processes including non-sandboxed Developer ID apps? If this is an intentional change, is Full Disk Access the expected requirement going forward, or is there a more targeted entitlement or Apple-recommended approach for a non-sandboxed app that legitimately needs to access browser directories as part of an extension deployment workflow?
Replies
1
Boosts
0
Views
231
Activity
1w
On File System Permissions
Modern versions of macOS use a file system permission model that’s far more complex than the traditional BSD rwx model, and this post is my attempt at explaining that model. If you have a question about this, post it here on DevForums. Put your thread in the App & System Services > Core OS topic area and tag it with Files and Storage. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = "eskimo" + "1" + "@" + "apple.com" On File System Permissions Modern versions of macOS have five different file system permission mechanisms: Traditional BSD permissions Access control lists (ACLs) App Sandbox Mandatory access control (MAC) Endpoint Security (ES) The first two were introduced a long time ago and rarely trip folks up. The second two are newer, more complex, and specific to macOS, and thus are the source of some confusion. Finally, Endpoint Security allows third-party developers to deny file system operations based on their own criteria. This post offers explanations and advice about all of these mechanisms. Error Codes App Sandbox and the mandatory access control system are both implemented using macOS’s sandboxing infrastructure. When a file system operation fails, check the error to see whether it was blocked by this sandboxing infrastructure. If an operation was blocked by BSD permissions or ACLs, it fails with EACCES (Permission denied, 13). If it was blocked by something else, it’ll fail with EPERM (Operation not permitted, 1). If you’re using Foundation’s FileManager, these error are both reported as Foundation errors, for example, the NSFileReadNoPermissionError error. To recover the underlying error, get the NSUnderlyingErrorKey property from the info dictionary. App Sandbox File system access within the App Sandbox is controlled by two factors. The first is the entitlements on the main executable. There are three relevant groups of entitlements: The com.apple.security.app-sandbox entitlement enables the App Sandbox. This denies access to all file system locations except those on a built-in allowlist (things like /System) or within the app’s containers. The various “standard location” entitlements extend the sandbox to include their corresponding locations. The various “file access temporary exceptions” entitlements extend the sandbox to include the items listed in the entitlement. Collectively this is known as your static sandbox. The second factor is dynamic sandbox extensions. The system issues these extensions to your sandbox based on user behaviour. For example, if the user selects a file in the open panel, the system issues a sandbox extension to your process so that it can access that file. The type of extension is determined by the main executable’s entitlements: com.apple.security.files.user-selected.read-only results in an extension that grants read-only access. com.apple.security.files.user-selected.read-write results in an extension that grants read/write access. Note There’s currently no way to get a dynamic sandbox extension that grants executable access. For all the gory details, see this post. These dynamic sandbox extensions are tied to your process; they go away when your process terminates. To maintain persistent access to an item, use a security-scoped bookmark. See Accessing files from the macOS App Sandbox. To pass access between processes, use an implicit security scoped bookmark, that is, a bookmark that was created without an explicit security scope (no .withSecurityScope flag) and without disabling the implicit security scope (no .withoutImplicitSecurityScope flag)). If you have access to a directory — regardless of whether that’s via an entitlement or a dynamic sandbox extension — then, in general, you have access to all items in the hierarchy rooted at that directory. This does not overrule the MAC protection discussed below. For example, if the user grants you access to ~/Library, that does not give you access to ~/Library/Mail because the latter is protected by MAC. Finally, the discussion above is focused on a new sandbox, the thing you get when you launch a sandboxed app from the Finder. If a sandboxed process starts a child process, that child process inherits its sandbox from its parent. For information on what happens in that case, see the Note box in Enabling App Sandbox Inheritance. IMPORTANT The child process inherits its parent process’s sandbox regardless of whether it has the com.apple.security.inherit entitlement. That entitlement exists primarily to act as a marker for App Review. App Review requires that all main executables have the com.apple.security.app-sandbox entitlement, and that entitlements starts a new sandbox by default. Thus, any helper tool inside your app needs the com.apple.security.inherit entitlement to trigger inheritance. However, if you’re not shipping on the Mac App Store you can leave off both of these entitlement and the helper process will inherit its parent’s sandbox just fine. The same applies if you run a built-in executable, like /bin/sh, as a child process. When the App Sandbox blocks something, it might generates a sandbox violation report. For information on how to view these reports, see Discovering and diagnosing App Sandbox violations. To learn more about the App Sandbox, see the various links in App Sandbox Resources. For information about how to embed a helper tool in a sandboxed app, see Embedding a Command-Line Tool in a Sandboxed App. Mandatory Access Control Mandatory access control (MAC) has been a feature of macOS for many releases, but it’s become a lot more prominent since macOS 10.14. There are many flavours of MAC but the ones you’re most likely to encounter are: Full Disk Access (macOS 10.14 and later) Files and Folders (macOS 10.15 and later) App bundle protection (macOS 13 and later) App container protection (macOS 14 and later) App group container protection (macOS 15 and later) Data Vaults (see below) and other internal techniques used by various macOS subsystems The exact list of file system locations protected by MAC is not documented and, as illustrated by the list above, can change over time. If your process runs into a MAC check the system might prompt the user to grant the process access, or it might just fail the access. If the user grants the process access, the system might only grant that access for this specific process, or it might persist that access for the program that this process is running. The exact behaviour varies based on the specific location in the file system and can also vary between different versions of macOS. Mandatory access control, as the name suggests, is mandatory; it’s not an opt-in like the App Sandbox. Rather, all processes on the system, including those running as root, as subject to MAC. Data Vaults are not a third-party developer opportunity. See this post if you’re curious. In the Full Disk Access and Files and Folders cases, users grant a program a MAC privilege using System Settings > Privacy & Security. Some MAC privileges are per user (Files and Folders) and some are system wide (Full Disk Access). If you’re not sure, run this simple test: On a Mac with two users, log in as user A and enable the MAC privilege for a program. Now log in as user B. Does the program have the privilege? If a process tries to access an item restricted by MAC, the system may prompt the user to grant it access there and then. For example, if an app tries to access the desktop, you’ll see an alert like this: “AAA” would like to access files in your Desktop folder. [Don’t Allow] [OK] To customise this message, set Files and Folders properties in your Info.plist. This system only displays this alert once. It remembers the user’s initial choice and returns the same result thereafter. This relies on your code having a stable code signing identity. If your code is unsigned, or signed ad hoc (Signed to Run Locally in Xcode parlance), the system can’t tell that version N+1 of your code is the same as version N, and thus you’ll encounter excessive prompts. Note For information about how that works, see TN3127 Inside Code Signing: Requirements. The Files and Folders prompts only show up if the process is running in a GUI login session. If not, the operation is allowed or denied based on existing information. If there’s no existing information, the operation is denied by default. For more information about app and app group container protection, see the links in Trusted Execution Resources. For more information about app groups in general, see App Groups: macOS vs iOS: Working Towards Harmony On managed systems the site admin can use the com.apple.TCC.configuration-profile-policy payload to assign MAC privileges. For testing purposes you can reset parts of TCC using the tccutil command-line tool. For general information about that tool, see its man page. For a list of TCC service names, see the posts on this thread. Note TCC stands for transparency, consent, and control. It’s the subsystem within macOS that manages most of the privileges visible in System Settings > Privacy & Security. TCC has no API surface, but you see its name in various places, including the above-mentioned configuration profile payload and command-line tool, and the name of its accompanying daemon, tccd. While tccutil is an easy way to do basic TCC testing, the most reliable way to test TCC is in a VM, restoring to a fresh snapshot between each test. If you want to try this out, crib ideas from Testing a Notarised Product. The MAC privilege mechanism is heavily dependent on the concept of responsible code. For example, if an app contains a helper tool and the helper tool triggers a MAC prompt, we want: The app’s name and usage description to appear in the alert. The user’s decision to be recorded for the whole app, not that specific helper tool. That decision to show up in System Settings under the app’s name. For this to work the system must be able to tell that the app is the responsible code for the helper tool. The system has various heuristics to determine this and it works reasonably well in most cases. However, it’s possible to break this link. I haven’t fully research this but my experience is that this most often breaks when the child process does something ‘odd’ to break the link, such as trying to daemonise itself. If you’re building a launchd daemon or agent and you find that it’s not correctly attributed to your app, add the AssociatedBundleIdentifiers property to your launchd property list. See the launchd.plist man page for the details. Scripting MAC presents some serious challenges for scripting because scripts are run by interpreters and the system can’t distinguish file system operations done by the interpreter from those done by the script. For example, if you have a script that needs to manipulate files on your desktop, you wouldn’t want to give the interpreter that privilege because then any script could do that. The easiest solution to this problem is to package your script as a standalone program that MAC can use for its tracking. This may be easy or hard depending on the specific scripting environment. For example, AppleScript makes it easy to export a script as a signed app, but that’s not true for shell scripts. TCC and Main Executables TCC expects its bundled clients — apps, app extensions, and so on — to use a native main executable. That is, it expects the CFBundleExecutable property to be the name of a Mach-O executable. If your product uses a script as its main executable, you’re likely to encounter TCC problems. To resolve these, switch to using a Mach-O executable. For an example of how you might do that, see this post. Endpoint Security Endpoint Security (ES) is a general mechanism for third-party products to enforce custom security policies on the Mac. An ES client asks ES to send it events when specific security-relevant operations occur. These events can be notifications or authorisations. In the case of authorisation events, the ES client must either allow or deny the operation. As you might imagine, the set of security-relevant operations includes file system operations. For example, when you open a file using the open system call, ES delivers the ES_EVENT_TYPE_AUTH_OPEN event to any interested ES clients. If one of those ES client denies the operation, the open system call fails with EPERM. For more information about ES, see the Endpoint Security framework documentation. Originally ES clients operated system wide. macOS 27 introduced a new mechanism, es_new_descendants_client, that allows an ES client to operate on the process hierarchy rooted at the client itself. Revision History 2026-09-18 Extended the Endpoint Security section to discuss es_new_descendants_client. Clarified the scope of MAC. 2025-11-04 Added a discussion of Endpoint Security. Made numerous minor editorial changes. 2024-11-08 Added info about app group container protection. Clarified that Data Vaults are just one example of the techniques used internally by macOS. Made other editorial changes. 2023-06-13 Replaced two obsolete links with links to shiny new official documentation: Accessing files from the macOS App Sandbox and Discovering and diagnosing App Sandbox violations. Added a short discussion of app container protection and a link to WWDC 2023 Session 10053 What’s new in privacy. 2023-04-07 Added a link to my post about executable permissions. Fixed a broken link. 2023-02-10 In TCC and Main Executables, added a link to my native trampoline code. Introduced the concept of an implicit security scoped bookmark. Introduced AssociatedBundleIdentifiers. Made other minor editorial changes. 2022-04-26 Added an explanation of the TCC initialism. Added a link to Viewing Sandbox Violation Reports.  Added the TCC and Main Executables section. Made significant editorial changes. 2022-01-10 Added a discussion of the file system hierarchy. 2021-04-26 First posted.
Replies
0
Boosts
0
Views
14k
Activity
1w
Config Profil (Live Caller ID)
Hello everyone, I found an interesting post by a developer on social media that mentions that Apple has provided a new configuration profile. Is this a new feature? Does anyone have any additional information about it? And can anyone provide me with the link to download this profile?
Replies
1
Boosts
0
Views
184
Activity
1w
CarPlay Driving Task notification press handling
We're trying to add simple notifications to our CarPlay integration that should open certain template when pressed, but the issue is that when pressing this notification on CarPlay screen nothing is invoked in the code (presumably didReceive should be invoked). All works fine with the same notification but pressed on the iPhone screen - didReceive is invoked properly. How should I handle the action when push notification is pressed on CarPlay screen?
Replies
1
Boosts
0
Views
409
Activity
1w
Is suspended spawn + audit_token_t matching a supported security boundary for one exact macOS process occurrence?
I’m designing a macOS privileged-service boundary and I’d like to clarify whether a process-occurrence authentication pattern previously described by Apple DTS is a supported shipping security contract, rather than just behaviour that happens to work on current macOS. Target: current macOS 26.x, using public APIs only. Threat model An arbitrary hostile process may run as the same ordinary, non-admin login user as the application. The attacker can launch an exact second copy of the legitimately signed requester binary. The attacker cannot obtain administrator / Touch ID authorization and does not control root, SIP, Recovery, the kernel, or the code-signing infrastructure. Desired property After a fresh Human-authorized operation, a root LaunchDaemon should grant authority to one specific requester process occurrence, not to every process having the same code-signing identity. Apple DTS thread 842442 describes a pattern based on: launching the requester suspended with posix_spawn(..., POSIX_SPAWN_START_SUSPENDED); obtaining a name/task port for that process; reading its TASK_AUDIT_TOKEN; resuming the process; and accepting only Mach messages whose kernel audit trailer identifies that same process occurrence. Thread 842442 also describes this area as being on “thin compatibility ice”, which is why I do not want to build a security boundary on behaviour that Apple does not intend applications to rely on. My core question is: Can a shipping macOS application rely on a pre-bound audit_token_t obtained from a suspended child and compare it against the audit token in subsequent raw Mach message trailers as a supported security boundary for that exact process occurrence? In particular, I need to know whether the supported contract covers: distinguishing another process with the exact same signed executable; PID reuse after the original process exits; messages queued before or around sender termination; a Mach send right transferred to another process — does the receiver see the audit token of the process that actually sends each message?; later exec by the original process; and whether full audit_token_t equality is an appropriate supported comparison for this purpose. If that is not a supported shipping contract, is there a current public XPC API that provides the equivalent property: binding one privileged-service session to one exact process occurrence rather than merely to its code-signing identity? I’m specifically trying to distinguish: code identity = this is an approved executable from mission authority = this one particular authorized process occurrence I’m happy with a negative answer if macOS does not expose a stable public contract for the latter. Related Apple DTS discussion: https://developer.apple.com/forums/thread/842442
Replies
11
Boosts
0
Views
652
Activity
1w
Endpoint Security: preventing exec after the ES client disconnects or exits
I'm evaluating Endpoint Security for a supervised macOS worker and a separate evidence collector. This is a question about supported API guarantees; I don't have a reproduced macOS bug. Before collection starts, I need to identify the worker's successful initial executable image. That image must remain current until every collector read and its resulting copy or storage operation has finished, including operations that ultimately report failure. Here, "remain current" means preventing replacement by a later successful exec, not preventing ordinary memory changes within the running program. The proposed policy would authorize the initial exec, then deny subsequent ES_EVENT_TYPE_AUTH_EXEC requests for that worker while collection is active. This is a design under consideration, not an implemented or tested guard. The unresolved case is loss of the ES client while a collector operation is already in flight. If the client crashes, is deleted, or disconnects: What happens to an exec authorization request already pending at that point? What governs later exec attempts after the client is gone? Can a supported mechanism keep exec replacement blocked until the collector's in-flight operations finish, while allowing shutdown within a finite bound? A later health check would not cover an interval in which replacement was already allowed. I reviewed Apple's WWDC20 Endpoint Security session, but haven't established a documented client-loss guarantee for this requirement. I'm asking about client loss separately from an authorization-response deadline expiring. Please point me to the applicable public API contract, including macOS/SDK availability and entitlement requirements. If Endpoint Security cannot provide this guarantee, that limitation would help me reconsider the design. Any supported ordering requirement for establishing the initial successful exec before the first collector read would also be useful.
Replies
6
Boosts
0
Views
1.1k
Activity
1w
StoreKit returns 0 products for 6 valid subscriptions in TestFlight
I am troubleshooting a reproducible StoreKit product discovery issue in a TestFlight build of my iOS application. App: Bundle ID: com.aileguvende.app Version: 2.9.59 Build: 97 On a physical iPhone using the TestFlight build, opening the subscription/paywall screen reproduces the issue. StoreKit availability is true and canMakePayments is true, but Product.products(for:) requests six auto-renewable subscription identifiers and returns: Requested products: 6 Returned products: 0 Not found products: 6 The query reports product_query_error with the plugin error code storekit_no_response. No purchase or Restore operation is required to reproduce the issue. The applicable TN3186 checks completed successfully: the App ID is explicit, In-App Purchase capability is enabled, the bundle ID and signing profile match, all six product identifiers match App Store Connect, all six products are available in Türkiye, pricing is configured, Turkish and English localizations are present, and the Paid Apps Agreement, banking, and tax information are active. The Apple Account and storefront are Türkiye. During the same runtime window, storekitd and appstored activity was observed and AMSErrorDomain activity was present, but no reliable native numeric error code or native product counts were exposed. CLIENT_PLUGIN_DEFECT_PROVEN=NO OFFICIAL_APPLE_INCIDENT_CONFIRMED=NO Feedback Assistant report: FB24793792. Could Apple engineers please verify: Whether the six subscriptions are present in the TestFlight/Sandbox commerce catalog for com.aileguvende.app. Whether the app-to-subscription catalog association is healthy on Apple’s backend. Whether there is a current StoreKit/App Store Commerce product-discovery issue where Product.products(for:) returns an empty result despite TN3186 checks passing. Whether any additional diagnostic is needed for FB24793792. This issue is reproducible without a transaction. I am not requesting a source-code change or a new build.
Replies
1
Boosts
0
Views
117
Activity
1w