Posts under App & System Services topic

Post

Replies

Boosts

Views

Activity

[SwiftData]Is it safe to reference previous VersionedSchema types in a newer schema's models array?
I'm building a SwiftData migration strategy and want to confirm whether it's officially supported to reference types from a previous VersionedSchema in a newer version's models array. Setup V1 defines all 28 models under its own namespace: static let versionIdentifier = Schema.Version(1, 0, 0) static let models: [any PersistentModel.Type] = [ Self.ItemModel.self, Self.UserModel.self, // ... 28 models ] } When migrating to V2, only ItemModel changes. To avoid copying unchanged model definitions into every new schema version, I include the previous version's types directly in V2's models array: static let versionIdentifier = Schema.Version(2, 0, 0) static let models: [any PersistentModel.Type] = [ Self.ItemModel.self, // V2 type (changed) ApplicationDatabaseSchema_V1_0_0.UserModel.self, // V1 type (unchanged) // ... other unchanged models referencing V1 types ] } extension ApplicationDatabaseSchema_V2_0_0 { @Model final class ItemModel { /* updated definition */ } } Questions Since SwiftData uses the simple class name (not the fully-qualified name including namespace) as the entity name, this appears to work in basic testing. But is mixing types from different schema version namespaces in a single models array officially supported, especially when models have relationships across versions? How does SwiftData handle inverse relationships when a newly defined V2 model references an unchanged V1 model? Is there a risk of schema corruption, runtime crashes during migration, or breaking changes in future SwiftData/iOS updates? The alternative — duplicating all 28 model class definitions in every schema version — introduces significant maintenance overhead. What is the recommended pattern for handling unchanged models with relationships when migrating using VersionedSchema? The alternative — duplicating all 28 model class definitions in every schema version — introduces significant maintenance overhead. Is there a recommended pattern for handling unchanged models when migrating with VersionedSchema?
1
0
102
1w
CallKit Call Directory database corruption (sqlite Code 11)
Hi everyone, I’ve filed a Feedback report (FB20986470) for a serious issue affecting the Call Directory database when add phone numbers for call blocking. When adding blocking numbers to a Call Directory extension, the system’s CallKit database (/private/var/mobile/Library/CallDirectory/CallDirectory.db) becomes corrupted. The reload call (reloadExtensionWithIdentifier) fails with error code 11 when the system tries to insert blocking entries, and the Console app on macOS shows the following errors: database corruption page 2265525 of /private/var/mobile/Library/CallDirectory/CallDirectory.db at line 81343 of [f0ca7bba1c] database corruption at line 79387 of [f0ca7bba1c] Error Domain=com.apple.callkit.database.sqlite Code=11 "sqlite3_step for query 'INSERT INTO PhoneNumberBlockingEntry (extension_id, phone_number_id) VALUES (?, (SELECT id FROM PhoneNumber WHERE (number = ?))), (?, (SELECT id FROM PhoneNumber WHERE (number = ?))),...)'" After this happens, CallKit becomes fully corrupted on the device and no further numbers can be added, even after: Disabling and re-enabling the extension Restarting the device (either force or soft restart) Reinstalling the app Waiting for a couple of minutes after this issue happens (that CallKit could possibly self-recovered) I also tested other call-blocking apps, and they all fail with the same error. The only thing that recovers the system is a full “Reset All Settings.” This issue has been reported by many users of my app, across multiple iOS versions and devices. Similar related issue reported by another developer: https://developer.apple.com/forums/thread/806129 Steps to Reproduce: Enable the Call Directory extension from a call-blocking app. Add and reload blocking numbers (a few thousand entries). Perform multiple reloads between additions. Check the Console, the corruption errors appear. From this point, all insert attempts fail system-wide. Expected Result: Entries should be inserted successfully, or the system should self-recover without persistent corruption. Actual Result: sqlite3_step fails with Code=11, and the Call Directory database remains corrupted until the user resets all settings. Additional Notes: All numbers are sorted and deduplicated before insertion. Happens intermittently after multiple reloads. The system log always shows internal database failure. Environment: Device: iPhone 16 Plus iOS 18.2 Beta (23C5027f) Xcode 16.1 (17B55) Attachments (included in Feedback FB20986470): sysdiagnose captured immediately after the failure (with Phone app General Profile) It seems like a system-level corruption affecting all Call Directory extensions once it occurs.
14
4
1.9k
1w
Apps do not trigger pop-up asking for permission to access local network on macOS Sequoia/Tahoe
We are having an issue with the Local Network permission pop-up not getting triggered for our apps that need to communicate with devices via local network interfaces/addresses. As we understand, apps using UDP should trigger this, causing macOS to prompt for access, or, if denied, fail to connect. However, we are facing issues with macOS not prompting this popup at all. Here are important and related points: Our application is packaged as a .app package and distributed independently (not on the App Store). The application controls hardware that we manufacture. In order to find the hardware on the network, we send a UDP broadcast with a message for our hardware on the local network, and the hardware responds with a message back. However, the popup (to ask for permission) never shows up. The application is not able to find the hardware device. It is interesting to note that data is still sent out to the network (without the popup) but we receive back the wrong data. The behaviour is consistent macOS Sequoia (and above) with both Apple And Intel silicon. Workarounds that have been tried: Manual Authorization: One solution suggested in various blogs was to go to "Settings → Privacy and Security-> Local network", find your application and grant access. However, the application never shows up in the list here. Firewall: No difference is seen in behaviour with firewall being ON OR OFF. Setting NSLocalNetworkUsageDescription: We have also tried setting the Info.plist adding the NSLocalNetworkUsageDescription with a meaningful string and updating the NSBonjourServices. Running Via terminal (WORKS): Running the application via terminal sees no issues. The application runs correctly and is able to send UDP and receive correct data (and find the devices on the network). But this is not an appropriate solution. How can we get this bug/issue fixed in macOS Sequoia (and above)? Are there any other solutions/workarounds that we can try on our end?
17
1
2.3k
1w
InstallerSection plugins no longer load on macOS 27 beta 5+ — Installer symlinks the bundle's Contents/, which breaks AMFI validation
We maintain a macOS product whose installer uses custom InstallerSection plugin bundles to show configuration panes during install. Starting with macOS 27 beta 6, all of our plugins stopped loading in Installer.app — the panes never appear and the install fails because our preinstall step depends on data the panes collect. The exact same .pkg works on macOS 26.6, and per thread 842811 the same bundles were fine on 27 betas 1–4(I have tested it from beta 6 onwards). While investigating we found what looks like the underlying cause, and it's reproducible by hand. THE FINDING During a failing install, look inside the extracted plugin bundle while the Installer window is still open: ls -la /private/tmp/com.apple.installer*/.bundle/Contents/ That layout fails code-signature validation. You can reproduce the failure manually, no Installer involved: codesign -vvv "/private/tmp/com.apple.installer"*/.bundle → .bundle: Too many levels of symbolic links WHAT THE SYSTEM LOGS SHOW amfid rejects the plugin executable: /private/tmp/com.apple.installerXXXXXX/.bundle/Contents/MacOS/ not valid: Error Domain=AppleMobileFileIntegrityError Code=-420 "The signature on the file is invalid" with repeated "UNIX error exception: 62" (errno 62 = ELOOP, too many levels of symbolic links) in backtraces through BundleDiskRep::component → SecStaticCode::component → validateNonResourceComponents → staticValidateCore, and "Code failed basic validity check (error: 100062)". For a Developer ID–signed plugin the kernel then treats it as fatal: AMFI: When validating /private/tmp/com.apple.installerXXXXXX/.bundle/Contents/MacOS/: The code contains a Team ID, but validating its signature failed. mac_vnode_check_signature: ... code signature validation failed fatally check_signature[pid: N]: error = 1 The plugin is never dlopen'd and the pane never appears. QUESTIONS Is there a way to get Installer to deploy the bundle with real files — or any other workaround? Note : I have Filed via Feedback Assistant as FB24601496; this overlaps FB24415432 / thread https://developer.apple.com/forums/thread/842811, which we've cross-referenced I have experienced this issue on latest Beta 8 build also -27.0 Beta (26A5425a)
3
3
606
1w
iOS 27 Health permissions: a reckoning is coming
iOS 27 adds a second stage to HealthKit read authorization. After picking data types, the user chooses "Past 30 Days and Future Data" or "All Recorded Data and Future Data", with Allow disabled until one is selected. Every user of every health app now makes this call, in the first seconds of onboarding, with no real context about what the app needs. I don't think the scale of this has landed yet. A meaningful share of users will pick 30 days. multi-year health trends, month to month comparisons, all-time records: with 30 days these features don't get worse, they stop existing. And it breaks silently. The user sees empty charts and a app that doesn't do what the screenshots promised. They won't connect that to a sheet they tapped through on day one — they'll connect it to the app. That's the reckoning: a wave of one-star reviews and support mail for a decision the developer never saw and can't inspect. Because we can't inspect it .authorizationStatus(for:) deliberately hides read authorization and getRequestStatusForAuthorization only says whether prompting would show UI, so a 30-day grant and a genuinely new Apple Watch user look identical from the query layer. A callback when Health permissions change for a type — even without disclosing the new state — would go a long way here. And we can't route users to the fix. UIApplication.openSettingsURLString opens the app's own Settings page, which has no Health section. The real control sits at Settings › Privacy & Security › Health › — four levels deep, unreachable from any public API. My suggestion is a URL constant scoped to the calling app, the way openNotificationSettingsURLString (iOS 15.4+) and openDefaultApplicationsSettingsURLString (iOS 18.3+) already work. But that's just my idea; if there's a better mitigation, or something already planned, I'd like to hear it. Worth saying the privacy gain looks thin either way: the app keeps all future data indefinitely, so a 30-day grant becomes a full-history grant in thirty days for anyone who keeps the app. The window limits what's readable today, not what accumulates. iOS 27 release is approaching... I think this will cause problems 😞 Filed as FB24398048 and FB24398031
1
0
754
1w
iOS Dynamically loaded custom fonts in WidgetKit not working on real device (simulator is fine). Sandbox chronod deny file-read-data for font file.
Project structure is: App target + widget extension + widget intent extension All share a common appgroup group.com.x.y and all file handling is done using FileManager.default.containerURL(forSecurityApplicationGroupIdentifier: "group.com.x.y") so that only the shared container is used. Using the Main app target, a font "Chewy-Regular.ttf" is downloaded and saved to the shared AppGroup container. Font can now be loaded via CTFontManagerRegisterFontsForURL and displayed in a Main App Text view Text("Testing...").font(Font.custom("Chewy-Regular", size: 20)) Now add a Widgetkit widget instance that uses this font. In 'getTimeLine() and getSnapShot() of IntentTimelineProvider we load the font again via CTFontManagerRegisterFontsForURL (this needs to happen again probably because widget runs in a separate process from the main app?). On simulator, the widget will show the correct font. BUT On iPhone7 real device, the widget will show the 'redacted placeholder view'. It seems that something is crashing. I see in the device console : error 14:39:07.567120-0800 chronod No configuration found for configured widget identifier: D9BF75EE-4A04-441A-8C85-1507F7ECE379 fault 14:39:07.625600-0800 widgetxExtension -[EXSwiftUI_Subsystem beginUsing:withBundle:] unexpectedly called multiple times. error 14:39:07.672733-0800 chronod Encountered an error reading the view archive for <private>; error: <private> error 14:39:07.672799-0800 chronod [co.appevolve.onewidget.widgetx:widgetx:small:1536744920620481560@148.0/148.0/20.2] reload: could not decode view error 14:39:07.674984-0800 kernel Sandbox: chronod(2128) deny(1) file-read-metadata /private/var/mobile/Containers/Shared/AppGroup/9B524570-1765-4C24-9E0C-15BC3982F0DC/downloadedFonts/Chewy/Chewy-Regular.ttf error 14:39:07.675762-0800 kernel Sandbox: chronod(2128) deny(1) file-read-data /private/var/mobile/Containers/Shared/AppGroup/9B524570-1765-4C24-9E0C-15BC3982F0DC/downloadedFonts/Chewy/Chewy-Regular.ttf error 14:39:07.708914-0800 chronod [u 8D2C83B3-A6CB-432E-A9D4-9BC8F7056B10:m (null)] [<private>(<private>)] Connection to plugin invalidated while in use. fault 14:39:07.710284-0800 widgetxExtension -[EXSwiftUI_Subsystem beginUsing:withBundle:] unexpectedly called multiple times. error 14:39:07.803468-0800 chronod Encountered an error reading the view archive for <private>; error: <private> It seems that it's a permission issue, and the textview can't access the font file it needs when the widget is rendering. Notes: 1) Font is definitely registered because I can see them in for fontFamily in UIFont.familyNames {             for fontName in UIFont.fontNames(forFamilyName: fontFamily) {                 print(fontName) 								... in both the Main App target and the Widget Extension target 2) If I make make the font part of the app bundle and add to 'Fonts provided by application' , the are loaded absolutely fine in the Main App and the Widget on simulator and iPhone 7 real device. 3) I do see this error sometimes in the Widget extension target log, don't know if it's related. widgetxExtension[1385:254599] [User Defaults] Couldn't read values in CFPrefsPlistSource<0x28375b880> (Domain: group.co.appevolve.onewidget, User: kCFPreferencesAnyUser, ByHost: Yes, Container: (null), Contents Need Refresh: Yes): Using kCFPreferencesAnyUser with a container is only allowed for System Containers, detaching from cfprefsd 4) I suspected something to do with app groups, so I tried to copy the font into the Widget Extension container and load from there, but had the same result. Please help! Thank you.
9
1
3.7k
1w
Can an iOS business app receive SMS from an existing business phone number?
Hello Apple Developer Support, I’m reaching out because my partner and I are developing a business application called ONIT, and we want to make sure we are using the correct Apple supported technology before moving forward with development. ONIT is designed for small businesses that receive customer communications through their existing business phone number. Our goal is to allow a business owner to connect their existing number to ONIT and have incoming customer SMS organized inside our application so they can see who needs a response, how long they have been waiting, and what the customer needs. The business would explicitly authorize ONIT to access these communications. We are not trying to access personal messages, and we are not looking to replace the Messages app. We need to understand what Apple supported API or entitlement would allow ONIT to receive incoming SMS associated with an existing business phone number. I have reviewed Apple’s TelephonyMessagingKit documentation and understand that it supports carrier based SMS, MMS, and RCS. However, our use case is specifically focused on receiving and organizing incoming messages rather than replacing the default messaging experience. Our main question is whether ONIT can receive incoming SMS from an existing business phone number, with the business owner’s authorization, without ONIT becoming the default carrier messaging app. If that is not possible through TelephonyMessagingKit, we would like to understand whether there is another Apple supported API, entitlement, or architecture that would allow a business to authorize ONIT to receive and organize incoming customer SMS. We would also appreciate clarification on whether this type of functionality requires carrier involvement and, if so, whether Apple recommends a particular architecture for connecting an existing business phone number to a third party business application while allowing the business to retain that same number. We are specifically trying to determine the technically and officially supported architecture before building our messaging infrastructure around it. If this question needs to be reviewed by another Apple team, we would greatly appreciate being directed to the appropriate team or documentation. Thank you for your time and assistance. Best regards, Kathryn Humphry Nawaf Almutairi Co-Founders,ONIT
0
0
90
1w
StoreKit Sandbox refund sheet consistently shows “Cannot Connect” — FB24527792
We are seeing a consistently reproducible StoreKit Sandbox issue involving Apple’s refund request sheet. Our app uses: Transaction.beginRefundRequest(for:) The refund sheet is successfully presented, but instead of loading the refund reason form, the Apple-provided sheet consistently displays: “Cannot Connect” This prevents the Sandbox refund request from being submitted. Environment: App: BTY Norebang Admin iOS: 26.6.1 Physical iPhone StoreKit environment: Sandbox Product type: Consumable Product: BTY Room – 1 Hour Development-signed build We have confirmed: Normal consumable purchase succeeds Transaction retrieval succeeds beginRefundRequest successfully presents Apple’s refund sheet App Store Server API calls succeed App Store Server Notifications V2 TEST delivery succeeds Get Test Notification Status reports sendAttemptResult = SUCCESS The problem persists after rebooting the device The problem persists after signing out and back into the Sandbox Apple Account Different network conditions have been tested The issue reproduces in an isolated Xcode/StoreKit test project with no BTY backend, authentication, or app networking dependency Expected behavior: The Sandbox refund request sheet should load the refund reason selection and allow the refund request to be submitted. Actual behavior: The Apple-provided refund sheet opens but displays “Cannot Connect.” No refund is submitted and no App Store Server Notification V2 REFUND event is generated. Feedback Assistant report: FB24527792 The Feedback Assistant report includes sysdiagnose and relevant diagnostic logs. This is currently the only remaining external blocker preventing us from completing full and prorated Sandbox refund end-to-end validation before enabling Production App Store Server Notifications. Could an Apple StoreKit / App Store Commerce engineer confirm whether this is a known Sandbox issue or advise whether any additional configuration or diagnostic information is required? We can provide a focused reproduction Xcode project, additional sysdiagnose logs, and Sandbox transaction details if needed.
0
0
138
1w
Family Controls "App and Website Usage" entitlement: .approvedWithDataAccess in development but .approved in TestFlight/App Store distribution
My app receives AuthorizationStatus.approvedWithDataAccess when run from a development build, but the identical code returns only .approved when run from a TestFlight / App Store (distribution) build. I'm trying to determine how to get the com.apple.developer.family-controls.app-and-website-usage entitlement granted for distribution, since enabling the capability in the portal has not been sufficient. Environment Xcode 26.6 (17F113) iPhone 17, iOS 26.5.2 App uses FamilyControls + ManagedSettings, plus Screen Time extensions (Shield Configuration, Shield Action, Device Activity, Live Activity, Control). Entitlement in question: com.apple.developer.family-controls.app-and-website-usage (iOS 26.4+) What works vs. what doesn't Development build (installed from Xcode): AuthorizationCenter.shared.authorizationStatus == .approvedWithDataAccess. FamilyActivityData.shared.installedApplications returns real bundle IDs and display names. TestFlight / distribution build (same source, same device, same OS): authorizationStatus == .approved. installedApplications is empty. The only variable between the two is development vs. distribution signing. What I've already done Enabled Family Controls App and Website Usage on the main App ID and on every extension identifier in Certificates, Identifiers & Profiles. Confirmed the entitlement key is present in the app's .entitlements and is signed into the distribution build. Regenerated the distribution provisioning profiles after enabling the capability (Automatically Manage Signing), archived a fresh build, ran Validate App (passed), and uploaded to TestFlight. Installed the TestFlight build on-device and verified in Settings that Authorization is still .approved. What I found in Capability Requests Under Certificates, Identifiers & Profiles -> the App ID, only Family Controls (base) shows as Assigned, its info panel lists Entitlement Keys = com.apple.developer.family-controls only. There is no entry anywhere in Capability Requests for com.apple.developer.family-controls.app-and-website-usage. So it appears there is no account-level distribution grant for the App and Website Usage tier for a distribution profile to inherit, which would explain why the checkbox alone doesn't take effect at runtime in distribution. I already have the base Family Controls distribution entitlement (the app ships and runs fine); it is specifically the App and Website Usage tier that works only in development. My questions Does the app-and-website-usage tier require a separate distribution approval (beyond enabling the checkbox on the App ID)? If so, where is that request submitted — it does not appear as a requestable item in my Capability Requests tab. Is there an additional step to make a distribution provisioning profile carry app-and-website-usage, given the base Family Controls entitlement already distributes correctly? For anyone who has shipped an app using .approvedWithDataAccess (iOS 26.4+): what did it take to get the usage tier active in an App Store/TestFlight build? I went through Developer Support; they confirmed the base Family Controls entitlement is on the account and directed me here for code-level guidance. Any pointers appreciated. Thank you!
1
0
224
1w
TCC Full Disk Access denied for Endpoint Security system extension on macOS 26, host app already granted FDA permission
I have developed an Endpoint Security (ES) system extension using Xcode 16.4. This extension is embedded inside its host application SecureGuard. The host app is signed with a Developer ID Application certificate, and I have created a dedicated ES system extension profile for SecureGuard FileGuard Extension. The workflow works perfectly on macOS 15.3.2. However, on macOS 26, although theSecureGuard host app launches and successfully installs/activates the ES extension, the ES extension gets rejected by TCC due to missing Full Disk Access authorization. I have explicitly granted Full Disk Access permission to the host SecureGuard application in the macOS System Settings. What I have verified so far: SIP was disabled for debugging on macOS 15.3.2, while SIP remains enabled on macOS 26. The app bundle is signed with Developer ID Application and successfully notarized via Apple’s notary service; the ES extension profile is also correctly configured. I do not believe SIP is the root cause here. On macOS 26, output from systemextensionsctl list shows: com.secureguard.fileguard.extension (2026.8/7.2) Extension [activated enabled] This confirms the system extension is successfully installed and activated, with valid code‑signing. I collected system logs with this command: log show --last 30m --predicate 'process CONTAINS "fileGuard"' --info --debug Repeated error messages appear: 14:00:42.271778+0800 0x7d38 Error 0x0 2246 0 com.secureguard.fileguard.extension: (libEndpointSecurity.dylib) Failed to open service: 0xe00002d8: Caller lacks TCC authorization for Full Disk Access For backward‑compatibility with older Intel‑based Mac hardware, both the SecureGuard host app and its ES system extension run under Rosetta translation. My hypothesis: when launchd spawns the ES extension process, TCC denies Full Disk Access for the extension itself, even though the parent host app already holds Full Disk Access permissions. Rosetta translation may potentially be a contributing factor. Has anyone encountered this TCC permission divergence between host app and Endpoint Security system extension on macOS 26? Are there any extra entitlement/profile requirements I missed?
4
0
741
1w
AlarmKit alarms fire late (or not until you wake up the iPhone)
Hey all, I've submitted a couple Feedback reports on this (FB22887867 on iOS 26 and FB24483266 on iOS 27), but wanted to share here for 1. validation that I'm not the only one experiencing this issue and 2. ask for ideas or experience with potential workarounds. The issue is that AlarmKit alarms, even when properly configured and scheduled from an app, will intermittently fire late, or not fire at all until the iPhone is woken up. For example, you might create an AlarmKit alarm with a relative schedule for 6:00am, then lock your iPhone before bed. When 6:00am passes, nothing happens. Then, at 6:13am it fires (with the full screen alert, audio and haptics) Or, you might wake up at 6:53am, notice that it didn't fire, tap the screen on your iPhone, the Lock Screen displays for about a second, then all of a sudden, the AlarmKit alert presents (with the full screen alert, audio and haptics). The issue has been present from iOS 26.0 up through the iOS 27.0 RC. I'm fairly confident that this is not a configuration issue. I've reproduced it using the WWDC 25 AlarmKit sample code and if you read from AlarmManager.shared.alarms, these alarms show up as expected: with a scheduled state and the correct times. The issue seems to be more common overnight, when the iPhone has been asleep for a while. It's less common on my personal iPhone but occurs probably once out of every 3 to 5 alarms on my test iPhones (which have much less interaction and background activity etc.). Of our app's few thousand daily users, we get complaints at least once a day. I've dropped a few sysdiagnose reports into Claude. In every instance, it claims that when the alarm was scheduled, mobiletimerd successfully registered an XPC wake-up for the alarm. However, during a completely unrelated event overnight (ex: a wifi packet), launchd drops the scheduled wake-up and nothing re-schedules it. So when 6:00am rolls around, nothing wakes up the iPhone to let the alarm fire. On days when it fires late, it's simply because another unrelated event (ex: a wifi packet) woke up the iPhone while the late alarm was queued. Looking forward to hearing your thoughts. Thank you.
1
0
211
1w
macOS Tahoe appears to ignore /etc/fstab ro and noauto — findings and workaround
macOS Tahoe appears to ignore /etc/fstab ro and noauto — findings and workaround I encountered what appears to be a regression in macOS Tahoe where Disk Arbitration no longer honors ro and noauto policies in /etc/fstab for external volumes. I am posting my findings here both to see whether others can reproduce the issue and to document a workaround, particularly for anyone using macOS for disk recovery or other workflows where preventing writes is important. The problem A configuration such as: UUID= none exfat noauto does not prevent the volume from automatically mounting. Similarly: UUID= none exfat ro does not result in a read-only mount. I also tested: UUID= none exfat ro,noauto with the same problem. This configuration worked for me before upgrading from macOS Sequoia to Tahoe. I initially suspected this might be related to Tahoe's newer exFAT/FSKit path, but testing APFS produced the same general behavior. It therefore appears to be broader than exFAT alone. /etc/fstab itself is being parsed correctly I tested the libc fstab interface using getfsent(). For example, an entry containing noauto is returned as: spec=UUID= | file=none | vfstype=exfat | mntops=noauto | type=rw So this does not appear to be a simple malformed-fstab problem. Tracing also shows diskarbitrationd accessing /etc/fstab. What Disk Arbitration is doing Unified logs from an affected exFAT mount show the filesystem being successfully probed, followed by Disk Arbitration mount approval callbacks. After approval, the reported mount options are: Mount options nodev,noowners,nosuid and the volume is then mounted successfully. The ro policy expected from /etc/fstab is notably absent from those mount options. Direct read-only mounting still works The filesystem itself is capable of being mounted read-only. For example, for exFAT: sudo mkdir -p /Volumes/Exchange sudo mount_exfat -o rdonly /dev/diskXsY /Volumes/Exchange This produces a genuinely read-only filesystem; a write test fails as expected. So at least in my testing, the problem appears to be associated with the normal Disk Arbitration mounting path rather than an inability of the filesystem to support read-only mounting. A working noauto workaround Disk Arbitration still supports mount approval callbacks. I tested a small client using: DAApprovalSessionCreate DARegisterDiskMountApprovalCallback DADissenterCreate The callback checks the volume UUID against /etc/fstab. If the corresponding entry contains noauto, it returns: kDAReturnNotPermitted This successfully prevents the volume from mounting. The test output looks like: [BLOCK] mount request: /dev/disk5s1 [BLOCK] mount request: /dev/disk5s2 The volume remains unmounted. Interestingly, this also blocks: diskutil mount /dev/diskXsY because diskutil mount goes through Disk Arbitration. A direct filesystem mount such as mount_exfat, however, bypasses that approval request and can still be used to deliberately mount the filesystem read-only. Why this matters For an ordinary external disk, an unexpected automount may only be annoying. For data recovery, forensic inspection, or a failing disk, the difference can be important. If /etc/fstab says: ro I expect that policy to protect the source filesystem from writes. Silently mounting the filesystem read-write instead means that the volume becomes available to Finder and other background services. That is exactly what I am trying to avoid when working with a recovery source. For this reason, I would recommend verifying the actual mount state rather than assuming that an existing /etc/fstab ro entry is still protecting a disk after upgrading to Tahoe. For example: mount or: diskutil info /dev/diskXsY should be used to confirm the resulting state. Current workaround design I am currently using a small compatibility helper that treats /etc/fstab as the source of truth: /etc/fstab ↓ compatibility helper ↓ Disk Arbitration mount approval The daemon side handles mount policy before Disk Arbitration can automatically mount the volume. An explicit mount helper can then perform a direct filesystem mount with the options specified in /etc/fstab, including read-only mounting where required. The intention is not to replace /etc/fstab, but to restore the behavior that was previously provided by the system. Reproduction request If anyone else is running macOS Tahoe, I would be interested to know whether you can reproduce this with either: UUID= none apfs noauto or: UUID= none exfat noauto and similarly with ro. Please be careful when testing ro: use a disposable/test volume rather than a disk whose contents actually depend on remaining read-only. I have also submitted this to Apple through Feedback Assistant. Feedback ID: 24677522 I will update this post if Apple provides additional information or if a later Tahoe update changes the behavior.
1
0
287
1w
CarPlay custom symbols missing on iOS 27
We’re seeing custom symbol images disappear in CarPlay on iOS 27.0. Their text labels remain visible, and built-in SF Symbols still display correctly. We reproduced this in a small standalone app using: CPGridButton in CPListTemplate.headerGridButtons CPListImageRowItemCondensedElement The custom symbol is an SVG symbol asset loaded from a resource bundle: UIImage(named: "chapters", in: resourceBundle, compatibleWith: nil)?.withRenderingMode(.alwaysTemplate) For comparison, the same screen displays the built-in dot.radiowaves.left.and.right symbol. On iOS 26.6.1, the custom symbol and built-in symbol appear correctly in both controls. On iOS 27.0, the custom symbol is missing from both controls, while the built-in symbol remains visible. The failing device is an iPhone 13 Pro running iOS 27.0 (24A437), with the sample built using Xcode 27.0 (27A266a). Has anyone else encountered this? Is this a known regression, or is there a new requirement forsupplying custom symbols to CarPlay? Filed as FB24806621, with the standalone project and comparison photos.
1
0
172
1w
CallKit does not activate audio session with higher probability after upgrading to iOS 18.4.1
Hi, We've noticed that this issue occurs more frequently after upgrading to iOS 18.4.1 and can result in one-way audio. Our app uses CallKit with WebRTC to establish VoIP connections. However, on iOS 18.4.1, CallKit no longer triggers: func provider(_ provider: CXProvider, didActivate audioSession: AVAudioSession) We're currently comparing the occurrence rate across different iOS versions to better understand the impact. Could you please help analyze the root cause of this issue?
40
1
4.9k
1w
Does "Connectivity Assist" bypass NEPacketTunnelProvider DNS interception on iOS 27?
We have a NEPacketTunnelProvider extension that intercepts and modifies DNS responses for specific hostnames as part of its normal operation. On iOS 27, we are seeing this interception being intermittently bypassed. Our extension still receives the DNS query, builds a response, and returns it promptly, but the client occasionally proceeds using a different address, presumably the actual DNS resolution result. This behavior does not reproduce on iOS 26 or earlier. The timing in our logs appears to correlate with the new Connectivity Assist feature (Settings → Wi-Fi), which Apple describes as using cellular data alongside Wi-Fi to improve reliability. Our suspicion is that Connectivity Assist may be performing DNS resolution over a cellular path in parallel, outside the tunnel, causing that resolution path to bypass our provider entirely. We have ruled out response timing and response format issues on our side. Varying the speed and format of our responses does not affect the outcome, suggesting that the behavior is occurring at a layer above the tunnel provider. We have the following questions: Does Connectivity Assist perform DNS resolution on a network path that can bypass an active NEPacketTunnelProvider? Is there any API, entitlement, or supported mechanism to disable Connectivity Assist for an app, or to ensure that all DNS resolution is routed through the active tunnel, similar to previous Wi-Fi Assist opt-out capabilities? Would a NEDNSProxyProvider-based DNS proxy be affected in the same way, or does it operate at a layer that Connectivity Assist cannot bypass? Any guidance, references to relevant documentation, WWDC session content, or confirmation of the expected behavior would be greatly appreciated.
5
0
787
1w
Is DeviceActivitySchedule a supported way to wake an extension for periodic work?
I'm building a parental-control app using FamilyControls, ManagedSettings and DeviceActivity. A guardian can lock a child's device from their own device, and the child's device applies the shield locally. The delivery problem: a background push can't wake our app once it has been force-quit, which is common on a child's device, so guardian-initiated changes sit undelivered until the child happens to open the app. I've found that DeviceActivityMonitorExtension still receives intervalDidStart / intervalDidEnd while the app is force-quit, and that a URLSession request started from the extension completes. So I could register a couple of short recurring DeviceActivitySchedule activities purely to wake the extension every ~15 minutes, check the server, and apply the resulting shield. My question: is using DeviceActivitySchedule purely as a wake mechanism — where the schedule doesn't correspond to any real usage-monitoring window — a supported use of the API, or is it working by accident? I'd rather not build on it if it's the latter. Two smaller ones, if anyone knows: Is network activity from the monitor extension expected to be given time to complete, and is there a documented execution budget? I've seen reports here that the extension stops being invoked after some days without the host app launching. Is that expected, and what re-arms it? If there's a supported mechanism for this that I've missed, I'd much rather use it.
0
0
95
1w
StoreKit 2 currentEntitlements persists after Sandbox Purchase History reset in TestFlight
I am testing a StoreKit 2 non-consumable IAP through TestFlight. Product ID: com.metabolla.plus.lifetime Type: Non-Consumable Environment: TestFlight / Sandbox Transaction.currentEntitlements keeps returning an active entitlement for this product even after: configuring a Sandbox Apple Account clearing Sandbox Purchase History reinstalling the app rebooting the device Important detail: the first TestFlight purchase was completed before configuring the Sandbox Apple Account on the device. If I temporarily change the Product ID in code, the entitlement disappears, so the issue seems tied to the original Product ID/account/receipt. Question: Can a non-consumable TestFlight purchase made before Sandbox Apple Account configuration remain associated with the original TestFlight/Apple ID identity? Is there any supported way to clear this entitlement for testing?
5
1
1.4k
1w
Guideline 3.1.3(d) vs. EU External Purchase Link Entitlement — real-time one-to-many servic
Hello, We are the developers of UbiFit Go, a fitness marketplace app (Portugal/EU). We offer live, real-time group fitness classes via video call, purchased as a credit pack exclusively on our external website (Stripe), and consumed in-app via a native button — with no links, buttons, or WebViews pointing to our website inside the app (only static informational text, e.g. "manage your credits from your account on our website"). Guideline 3.1.3(d) states that "one-to-few and one-to-many real-time services must use in-app purchase." We would like to confirm: Does this static-text-only pattern (no in-app link of any kind) still fall under 3.1.3(d), or is it exempt because there is no purchase flow or redirection happening inside the app at all? If it does fall under 3.1.3(d), does the EU External Purchase Link Entitlement (per the Digital Markets Act) apply to real-time one-to-many services such as live group fitness classes, or is that entitlement limited to non-real-time digital goods? We want to ensure full compliance before implementing this feature. Thank you.
0
0
68
1w
[SwiftData]Is it safe to reference previous VersionedSchema types in a newer schema's models array?
I'm building a SwiftData migration strategy and want to confirm whether it's officially supported to reference types from a previous VersionedSchema in a newer version's models array. Setup V1 defines all 28 models under its own namespace: static let versionIdentifier = Schema.Version(1, 0, 0) static let models: [any PersistentModel.Type] = [ Self.ItemModel.self, Self.UserModel.self, // ... 28 models ] } When migrating to V2, only ItemModel changes. To avoid copying unchanged model definitions into every new schema version, I include the previous version's types directly in V2's models array: static let versionIdentifier = Schema.Version(2, 0, 0) static let models: [any PersistentModel.Type] = [ Self.ItemModel.self, // V2 type (changed) ApplicationDatabaseSchema_V1_0_0.UserModel.self, // V1 type (unchanged) // ... other unchanged models referencing V1 types ] } extension ApplicationDatabaseSchema_V2_0_0 { @Model final class ItemModel { /* updated definition */ } } Questions Since SwiftData uses the simple class name (not the fully-qualified name including namespace) as the entity name, this appears to work in basic testing. But is mixing types from different schema version namespaces in a single models array officially supported, especially when models have relationships across versions? How does SwiftData handle inverse relationships when a newly defined V2 model references an unchanged V1 model? Is there a risk of schema corruption, runtime crashes during migration, or breaking changes in future SwiftData/iOS updates? The alternative — duplicating all 28 model class definitions in every schema version — introduces significant maintenance overhead. What is the recommended pattern for handling unchanged models with relationships when migrating using VersionedSchema? The alternative — duplicating all 28 model class definitions in every schema version — introduces significant maintenance overhead. Is there a recommended pattern for handling unchanged models when migrating with VersionedSchema?
Replies
1
Boosts
0
Views
102
Activity
1w
CallKit Call Directory database corruption (sqlite Code 11)
Hi everyone, I’ve filed a Feedback report (FB20986470) for a serious issue affecting the Call Directory database when add phone numbers for call blocking. When adding blocking numbers to a Call Directory extension, the system’s CallKit database (/private/var/mobile/Library/CallDirectory/CallDirectory.db) becomes corrupted. The reload call (reloadExtensionWithIdentifier) fails with error code 11 when the system tries to insert blocking entries, and the Console app on macOS shows the following errors: database corruption page 2265525 of /private/var/mobile/Library/CallDirectory/CallDirectory.db at line 81343 of [f0ca7bba1c] database corruption at line 79387 of [f0ca7bba1c] Error Domain=com.apple.callkit.database.sqlite Code=11 "sqlite3_step for query 'INSERT INTO PhoneNumberBlockingEntry (extension_id, phone_number_id) VALUES (?, (SELECT id FROM PhoneNumber WHERE (number = ?))), (?, (SELECT id FROM PhoneNumber WHERE (number = ?))),...)'" After this happens, CallKit becomes fully corrupted on the device and no further numbers can be added, even after: Disabling and re-enabling the extension Restarting the device (either force or soft restart) Reinstalling the app Waiting for a couple of minutes after this issue happens (that CallKit could possibly self-recovered) I also tested other call-blocking apps, and they all fail with the same error. The only thing that recovers the system is a full “Reset All Settings.” This issue has been reported by many users of my app, across multiple iOS versions and devices. Similar related issue reported by another developer: https://developer.apple.com/forums/thread/806129 Steps to Reproduce: Enable the Call Directory extension from a call-blocking app. Add and reload blocking numbers (a few thousand entries). Perform multiple reloads between additions. Check the Console, the corruption errors appear. From this point, all insert attempts fail system-wide. Expected Result: Entries should be inserted successfully, or the system should self-recover without persistent corruption. Actual Result: sqlite3_step fails with Code=11, and the Call Directory database remains corrupted until the user resets all settings. Additional Notes: All numbers are sorted and deduplicated before insertion. Happens intermittently after multiple reloads. The system log always shows internal database failure. Environment: Device: iPhone 16 Plus iOS 18.2 Beta (23C5027f) Xcode 16.1 (17B55) Attachments (included in Feedback FB20986470): sysdiagnose captured immediately after the failure (with Phone app General Profile) It seems like a system-level corruption affecting all Call Directory extensions once it occurs.
Replies
14
Boosts
4
Views
1.9k
Activity
1w
Apps do not trigger pop-up asking for permission to access local network on macOS Sequoia/Tahoe
We are having an issue with the Local Network permission pop-up not getting triggered for our apps that need to communicate with devices via local network interfaces/addresses. As we understand, apps using UDP should trigger this, causing macOS to prompt for access, or, if denied, fail to connect. However, we are facing issues with macOS not prompting this popup at all. Here are important and related points: Our application is packaged as a .app package and distributed independently (not on the App Store). The application controls hardware that we manufacture. In order to find the hardware on the network, we send a UDP broadcast with a message for our hardware on the local network, and the hardware responds with a message back. However, the popup (to ask for permission) never shows up. The application is not able to find the hardware device. It is interesting to note that data is still sent out to the network (without the popup) but we receive back the wrong data. The behaviour is consistent macOS Sequoia (and above) with both Apple And Intel silicon. Workarounds that have been tried: Manual Authorization: One solution suggested in various blogs was to go to "Settings → Privacy and Security-> Local network", find your application and grant access. However, the application never shows up in the list here. Firewall: No difference is seen in behaviour with firewall being ON OR OFF. Setting NSLocalNetworkUsageDescription: We have also tried setting the Info.plist adding the NSLocalNetworkUsageDescription with a meaningful string and updating the NSBonjourServices. Running Via terminal (WORKS): Running the application via terminal sees no issues. The application runs correctly and is able to send UDP and receive correct data (and find the devices on the network). But this is not an appropriate solution. How can we get this bug/issue fixed in macOS Sequoia (and above)? Are there any other solutions/workarounds that we can try on our end?
Replies
17
Boosts
1
Views
2.3k
Activity
1w
InstallerSection plugins no longer load on macOS 27 beta 5+ — Installer symlinks the bundle's Contents/, which breaks AMFI validation
We maintain a macOS product whose installer uses custom InstallerSection plugin bundles to show configuration panes during install. Starting with macOS 27 beta 6, all of our plugins stopped loading in Installer.app — the panes never appear and the install fails because our preinstall step depends on data the panes collect. The exact same .pkg works on macOS 26.6, and per thread 842811 the same bundles were fine on 27 betas 1–4(I have tested it from beta 6 onwards). While investigating we found what looks like the underlying cause, and it's reproducible by hand. THE FINDING During a failing install, look inside the extracted plugin bundle while the Installer window is still open: ls -la /private/tmp/com.apple.installer*/.bundle/Contents/ That layout fails code-signature validation. You can reproduce the failure manually, no Installer involved: codesign -vvv "/private/tmp/com.apple.installer"*/.bundle → .bundle: Too many levels of symbolic links WHAT THE SYSTEM LOGS SHOW amfid rejects the plugin executable: /private/tmp/com.apple.installerXXXXXX/.bundle/Contents/MacOS/ not valid: Error Domain=AppleMobileFileIntegrityError Code=-420 "The signature on the file is invalid" with repeated "UNIX error exception: 62" (errno 62 = ELOOP, too many levels of symbolic links) in backtraces through BundleDiskRep::component → SecStaticCode::component → validateNonResourceComponents → staticValidateCore, and "Code failed basic validity check (error: 100062)". For a Developer ID–signed plugin the kernel then treats it as fatal: AMFI: When validating /private/tmp/com.apple.installerXXXXXX/.bundle/Contents/MacOS/: The code contains a Team ID, but validating its signature failed. mac_vnode_check_signature: ... code signature validation failed fatally check_signature[pid: N]: error = 1 The plugin is never dlopen'd and the pane never appears. QUESTIONS Is there a way to get Installer to deploy the bundle with real files — or any other workaround? Note : I have Filed via Feedback Assistant as FB24601496; this overlaps FB24415432 / thread https://developer.apple.com/forums/thread/842811, which we've cross-referenced I have experienced this issue on latest Beta 8 build also -27.0 Beta (26A5425a)
Replies
3
Boosts
3
Views
606
Activity
1w
iOS 27 Health permissions: a reckoning is coming
iOS 27 adds a second stage to HealthKit read authorization. After picking data types, the user chooses "Past 30 Days and Future Data" or "All Recorded Data and Future Data", with Allow disabled until one is selected. Every user of every health app now makes this call, in the first seconds of onboarding, with no real context about what the app needs. I don't think the scale of this has landed yet. A meaningful share of users will pick 30 days. multi-year health trends, month to month comparisons, all-time records: with 30 days these features don't get worse, they stop existing. And it breaks silently. The user sees empty charts and a app that doesn't do what the screenshots promised. They won't connect that to a sheet they tapped through on day one — they'll connect it to the app. That's the reckoning: a wave of one-star reviews and support mail for a decision the developer never saw and can't inspect. Because we can't inspect it .authorizationStatus(for:) deliberately hides read authorization and getRequestStatusForAuthorization only says whether prompting would show UI, so a 30-day grant and a genuinely new Apple Watch user look identical from the query layer. A callback when Health permissions change for a type — even without disclosing the new state — would go a long way here. And we can't route users to the fix. UIApplication.openSettingsURLString opens the app's own Settings page, which has no Health section. The real control sits at Settings › Privacy & Security › Health › — four levels deep, unreachable from any public API. My suggestion is a URL constant scoped to the calling app, the way openNotificationSettingsURLString (iOS 15.4+) and openDefaultApplicationsSettingsURLString (iOS 18.3+) already work. But that's just my idea; if there's a better mitigation, or something already planned, I'd like to hear it. Worth saying the privacy gain looks thin either way: the app keeps all future data indefinitely, so a 30-day grant becomes a full-history grant in thirty days for anyone who keeps the app. The window limits what's readable today, not what accumulates. iOS 27 release is approaching... I think this will cause problems 😞 Filed as FB24398048 and FB24398031
Replies
1
Boosts
0
Views
754
Activity
1w
iOS Dynamically loaded custom fonts in WidgetKit not working on real device (simulator is fine). Sandbox chronod deny file-read-data for font file.
Project structure is: App target + widget extension + widget intent extension All share a common appgroup group.com.x.y and all file handling is done using FileManager.default.containerURL(forSecurityApplicationGroupIdentifier: "group.com.x.y") so that only the shared container is used. Using the Main app target, a font "Chewy-Regular.ttf" is downloaded and saved to the shared AppGroup container. Font can now be loaded via CTFontManagerRegisterFontsForURL and displayed in a Main App Text view Text("Testing...").font(Font.custom("Chewy-Regular", size: 20)) Now add a Widgetkit widget instance that uses this font. In 'getTimeLine() and getSnapShot() of IntentTimelineProvider we load the font again via CTFontManagerRegisterFontsForURL (this needs to happen again probably because widget runs in a separate process from the main app?). On simulator, the widget will show the correct font. BUT On iPhone7 real device, the widget will show the 'redacted placeholder view'. It seems that something is crashing. I see in the device console : error 14:39:07.567120-0800 chronod No configuration found for configured widget identifier: D9BF75EE-4A04-441A-8C85-1507F7ECE379 fault 14:39:07.625600-0800 widgetxExtension -[EXSwiftUI_Subsystem beginUsing:withBundle:] unexpectedly called multiple times. error 14:39:07.672733-0800 chronod Encountered an error reading the view archive for <private>; error: <private> error 14:39:07.672799-0800 chronod [co.appevolve.onewidget.widgetx:widgetx:small:1536744920620481560@148.0/148.0/20.2] reload: could not decode view error 14:39:07.674984-0800 kernel Sandbox: chronod(2128) deny(1) file-read-metadata /private/var/mobile/Containers/Shared/AppGroup/9B524570-1765-4C24-9E0C-15BC3982F0DC/downloadedFonts/Chewy/Chewy-Regular.ttf error 14:39:07.675762-0800 kernel Sandbox: chronod(2128) deny(1) file-read-data /private/var/mobile/Containers/Shared/AppGroup/9B524570-1765-4C24-9E0C-15BC3982F0DC/downloadedFonts/Chewy/Chewy-Regular.ttf error 14:39:07.708914-0800 chronod [u 8D2C83B3-A6CB-432E-A9D4-9BC8F7056B10:m (null)] [<private>(<private>)] Connection to plugin invalidated while in use. fault 14:39:07.710284-0800 widgetxExtension -[EXSwiftUI_Subsystem beginUsing:withBundle:] unexpectedly called multiple times. error 14:39:07.803468-0800 chronod Encountered an error reading the view archive for <private>; error: <private> It seems that it's a permission issue, and the textview can't access the font file it needs when the widget is rendering. Notes: 1) Font is definitely registered because I can see them in for fontFamily in UIFont.familyNames {             for fontName in UIFont.fontNames(forFamilyName: fontFamily) {                 print(fontName) 								... in both the Main App target and the Widget Extension target 2) If I make make the font part of the app bundle and add to 'Fonts provided by application' , the are loaded absolutely fine in the Main App and the Widget on simulator and iPhone 7 real device. 3) I do see this error sometimes in the Widget extension target log, don't know if it's related. widgetxExtension[1385:254599] [User Defaults] Couldn't read values in CFPrefsPlistSource<0x28375b880> (Domain: group.co.appevolve.onewidget, User: kCFPreferencesAnyUser, ByHost: Yes, Container: (null), Contents Need Refresh: Yes): Using kCFPreferencesAnyUser with a container is only allowed for System Containers, detaching from cfprefsd 4) I suspected something to do with app groups, so I tried to copy the font into the Widget Extension container and load from there, but had the same result. Please help! Thank you.
Replies
9
Boosts
1
Views
3.7k
Activity
1w
Can an iOS business app receive SMS from an existing business phone number?
Hello Apple Developer Support, I’m reaching out because my partner and I are developing a business application called ONIT, and we want to make sure we are using the correct Apple supported technology before moving forward with development. ONIT is designed for small businesses that receive customer communications through their existing business phone number. Our goal is to allow a business owner to connect their existing number to ONIT and have incoming customer SMS organized inside our application so they can see who needs a response, how long they have been waiting, and what the customer needs. The business would explicitly authorize ONIT to access these communications. We are not trying to access personal messages, and we are not looking to replace the Messages app. We need to understand what Apple supported API or entitlement would allow ONIT to receive incoming SMS associated with an existing business phone number. I have reviewed Apple’s TelephonyMessagingKit documentation and understand that it supports carrier based SMS, MMS, and RCS. However, our use case is specifically focused on receiving and organizing incoming messages rather than replacing the default messaging experience. Our main question is whether ONIT can receive incoming SMS from an existing business phone number, with the business owner’s authorization, without ONIT becoming the default carrier messaging app. If that is not possible through TelephonyMessagingKit, we would like to understand whether there is another Apple supported API, entitlement, or architecture that would allow a business to authorize ONIT to receive and organize incoming customer SMS. We would also appreciate clarification on whether this type of functionality requires carrier involvement and, if so, whether Apple recommends a particular architecture for connecting an existing business phone number to a third party business application while allowing the business to retain that same number. We are specifically trying to determine the technically and officially supported architecture before building our messaging infrastructure around it. If this question needs to be reviewed by another Apple team, we would greatly appreciate being directed to the appropriate team or documentation. Thank you for your time and assistance. Best regards, Kathryn Humphry Nawaf Almutairi Co-Founders,ONIT
Replies
0
Boosts
0
Views
90
Activity
1w
StoreKit Sandbox refund sheet consistently shows “Cannot Connect” — FB24527792
We are seeing a consistently reproducible StoreKit Sandbox issue involving Apple’s refund request sheet. Our app uses: Transaction.beginRefundRequest(for:) The refund sheet is successfully presented, but instead of loading the refund reason form, the Apple-provided sheet consistently displays: “Cannot Connect” This prevents the Sandbox refund request from being submitted. Environment: App: BTY Norebang Admin iOS: 26.6.1 Physical iPhone StoreKit environment: Sandbox Product type: Consumable Product: BTY Room – 1 Hour Development-signed build We have confirmed: Normal consumable purchase succeeds Transaction retrieval succeeds beginRefundRequest successfully presents Apple’s refund sheet App Store Server API calls succeed App Store Server Notifications V2 TEST delivery succeeds Get Test Notification Status reports sendAttemptResult = SUCCESS The problem persists after rebooting the device The problem persists after signing out and back into the Sandbox Apple Account Different network conditions have been tested The issue reproduces in an isolated Xcode/StoreKit test project with no BTY backend, authentication, or app networking dependency Expected behavior: The Sandbox refund request sheet should load the refund reason selection and allow the refund request to be submitted. Actual behavior: The Apple-provided refund sheet opens but displays “Cannot Connect.” No refund is submitted and no App Store Server Notification V2 REFUND event is generated. Feedback Assistant report: FB24527792 The Feedback Assistant report includes sysdiagnose and relevant diagnostic logs. This is currently the only remaining external blocker preventing us from completing full and prorated Sandbox refund end-to-end validation before enabling Production App Store Server Notifications. Could an Apple StoreKit / App Store Commerce engineer confirm whether this is a known Sandbox issue or advise whether any additional configuration or diagnostic information is required? We can provide a focused reproduction Xcode project, additional sysdiagnose logs, and Sandbox transaction details if needed.
Replies
0
Boosts
0
Views
138
Activity
1w
Family Controls "App and Website Usage" entitlement: .approvedWithDataAccess in development but .approved in TestFlight/App Store distribution
My app receives AuthorizationStatus.approvedWithDataAccess when run from a development build, but the identical code returns only .approved when run from a TestFlight / App Store (distribution) build. I'm trying to determine how to get the com.apple.developer.family-controls.app-and-website-usage entitlement granted for distribution, since enabling the capability in the portal has not been sufficient. Environment Xcode 26.6 (17F113) iPhone 17, iOS 26.5.2 App uses FamilyControls + ManagedSettings, plus Screen Time extensions (Shield Configuration, Shield Action, Device Activity, Live Activity, Control). Entitlement in question: com.apple.developer.family-controls.app-and-website-usage (iOS 26.4+) What works vs. what doesn't Development build (installed from Xcode): AuthorizationCenter.shared.authorizationStatus == .approvedWithDataAccess. FamilyActivityData.shared.installedApplications returns real bundle IDs and display names. TestFlight / distribution build (same source, same device, same OS): authorizationStatus == .approved. installedApplications is empty. The only variable between the two is development vs. distribution signing. What I've already done Enabled Family Controls App and Website Usage on the main App ID and on every extension identifier in Certificates, Identifiers & Profiles. Confirmed the entitlement key is present in the app's .entitlements and is signed into the distribution build. Regenerated the distribution provisioning profiles after enabling the capability (Automatically Manage Signing), archived a fresh build, ran Validate App (passed), and uploaded to TestFlight. Installed the TestFlight build on-device and verified in Settings that Authorization is still .approved. What I found in Capability Requests Under Certificates, Identifiers & Profiles -> the App ID, only Family Controls (base) shows as Assigned, its info panel lists Entitlement Keys = com.apple.developer.family-controls only. There is no entry anywhere in Capability Requests for com.apple.developer.family-controls.app-and-website-usage. So it appears there is no account-level distribution grant for the App and Website Usage tier for a distribution profile to inherit, which would explain why the checkbox alone doesn't take effect at runtime in distribution. I already have the base Family Controls distribution entitlement (the app ships and runs fine); it is specifically the App and Website Usage tier that works only in development. My questions Does the app-and-website-usage tier require a separate distribution approval (beyond enabling the checkbox on the App ID)? If so, where is that request submitted — it does not appear as a requestable item in my Capability Requests tab. Is there an additional step to make a distribution provisioning profile carry app-and-website-usage, given the base Family Controls entitlement already distributes correctly? For anyone who has shipped an app using .approvedWithDataAccess (iOS 26.4+): what did it take to get the usage tier active in an App Store/TestFlight build? I went through Developer Support; they confirmed the base Family Controls entitlement is on the account and directed me here for code-level guidance. Any pointers appreciated. Thank you!
Replies
1
Boosts
0
Views
224
Activity
1w
TCC Full Disk Access denied for Endpoint Security system extension on macOS 26, host app already granted FDA permission
I have developed an Endpoint Security (ES) system extension using Xcode 16.4. This extension is embedded inside its host application SecureGuard. The host app is signed with a Developer ID Application certificate, and I have created a dedicated ES system extension profile for SecureGuard FileGuard Extension. The workflow works perfectly on macOS 15.3.2. However, on macOS 26, although theSecureGuard host app launches and successfully installs/activates the ES extension, the ES extension gets rejected by TCC due to missing Full Disk Access authorization. I have explicitly granted Full Disk Access permission to the host SecureGuard application in the macOS System Settings. What I have verified so far: SIP was disabled for debugging on macOS 15.3.2, while SIP remains enabled on macOS 26. The app bundle is signed with Developer ID Application and successfully notarized via Apple’s notary service; the ES extension profile is also correctly configured. I do not believe SIP is the root cause here. On macOS 26, output from systemextensionsctl list shows: com.secureguard.fileguard.extension (2026.8/7.2) Extension [activated enabled] This confirms the system extension is successfully installed and activated, with valid code‑signing. I collected system logs with this command: log show --last 30m --predicate 'process CONTAINS "fileGuard"' --info --debug Repeated error messages appear: 14:00:42.271778+0800 0x7d38 Error 0x0 2246 0 com.secureguard.fileguard.extension: (libEndpointSecurity.dylib) Failed to open service: 0xe00002d8: Caller lacks TCC authorization for Full Disk Access For backward‑compatibility with older Intel‑based Mac hardware, both the SecureGuard host app and its ES system extension run under Rosetta translation. My hypothesis: when launchd spawns the ES extension process, TCC denies Full Disk Access for the extension itself, even though the parent host app already holds Full Disk Access permissions. Rosetta translation may potentially be a contributing factor. Has anyone encountered this TCC permission divergence between host app and Endpoint Security system extension on macOS 26? Are there any extra entitlement/profile requirements I missed?
Replies
4
Boosts
0
Views
741
Activity
1w
Sometimes CallKit doesn't send back audioSession didActivate
I'm having problem with my VoIP application. My app uses Callkit and VoIP push notification to make SIP calls between same app. Sometimes after taking the phone the call doesn't start. I found out iOS is not sending back audioSession didActive response to my app. Is this known issue or bug?
Replies
1
Boosts
0
Views
245
Activity
1w
AlarmKit alarms fire late (or not until you wake up the iPhone)
Hey all, I've submitted a couple Feedback reports on this (FB22887867 on iOS 26 and FB24483266 on iOS 27), but wanted to share here for 1. validation that I'm not the only one experiencing this issue and 2. ask for ideas or experience with potential workarounds. The issue is that AlarmKit alarms, even when properly configured and scheduled from an app, will intermittently fire late, or not fire at all until the iPhone is woken up. For example, you might create an AlarmKit alarm with a relative schedule for 6:00am, then lock your iPhone before bed. When 6:00am passes, nothing happens. Then, at 6:13am it fires (with the full screen alert, audio and haptics) Or, you might wake up at 6:53am, notice that it didn't fire, tap the screen on your iPhone, the Lock Screen displays for about a second, then all of a sudden, the AlarmKit alert presents (with the full screen alert, audio and haptics). The issue has been present from iOS 26.0 up through the iOS 27.0 RC. I'm fairly confident that this is not a configuration issue. I've reproduced it using the WWDC 25 AlarmKit sample code and if you read from AlarmManager.shared.alarms, these alarms show up as expected: with a scheduled state and the correct times. The issue seems to be more common overnight, when the iPhone has been asleep for a while. It's less common on my personal iPhone but occurs probably once out of every 3 to 5 alarms on my test iPhones (which have much less interaction and background activity etc.). Of our app's few thousand daily users, we get complaints at least once a day. I've dropped a few sysdiagnose reports into Claude. In every instance, it claims that when the alarm was scheduled, mobiletimerd successfully registered an XPC wake-up for the alarm. However, during a completely unrelated event overnight (ex: a wifi packet), launchd drops the scheduled wake-up and nothing re-schedules it. So when 6:00am rolls around, nothing wakes up the iPhone to let the alarm fire. On days when it fires late, it's simply because another unrelated event (ex: a wifi packet) woke up the iPhone while the late alarm was queued. Looking forward to hearing your thoughts. Thank you.
Replies
1
Boosts
0
Views
211
Activity
1w
macOS Tahoe appears to ignore /etc/fstab ro and noauto — findings and workaround
macOS Tahoe appears to ignore /etc/fstab ro and noauto — findings and workaround I encountered what appears to be a regression in macOS Tahoe where Disk Arbitration no longer honors ro and noauto policies in /etc/fstab for external volumes. I am posting my findings here both to see whether others can reproduce the issue and to document a workaround, particularly for anyone using macOS for disk recovery or other workflows where preventing writes is important. The problem A configuration such as: UUID= none exfat noauto does not prevent the volume from automatically mounting. Similarly: UUID= none exfat ro does not result in a read-only mount. I also tested: UUID= none exfat ro,noauto with the same problem. This configuration worked for me before upgrading from macOS Sequoia to Tahoe. I initially suspected this might be related to Tahoe's newer exFAT/FSKit path, but testing APFS produced the same general behavior. It therefore appears to be broader than exFAT alone. /etc/fstab itself is being parsed correctly I tested the libc fstab interface using getfsent(). For example, an entry containing noauto is returned as: spec=UUID= | file=none | vfstype=exfat | mntops=noauto | type=rw So this does not appear to be a simple malformed-fstab problem. Tracing also shows diskarbitrationd accessing /etc/fstab. What Disk Arbitration is doing Unified logs from an affected exFAT mount show the filesystem being successfully probed, followed by Disk Arbitration mount approval callbacks. After approval, the reported mount options are: Mount options nodev,noowners,nosuid and the volume is then mounted successfully. The ro policy expected from /etc/fstab is notably absent from those mount options. Direct read-only mounting still works The filesystem itself is capable of being mounted read-only. For example, for exFAT: sudo mkdir -p /Volumes/Exchange sudo mount_exfat -o rdonly /dev/diskXsY /Volumes/Exchange This produces a genuinely read-only filesystem; a write test fails as expected. So at least in my testing, the problem appears to be associated with the normal Disk Arbitration mounting path rather than an inability of the filesystem to support read-only mounting. A working noauto workaround Disk Arbitration still supports mount approval callbacks. I tested a small client using: DAApprovalSessionCreate DARegisterDiskMountApprovalCallback DADissenterCreate The callback checks the volume UUID against /etc/fstab. If the corresponding entry contains noauto, it returns: kDAReturnNotPermitted This successfully prevents the volume from mounting. The test output looks like: [BLOCK] mount request: /dev/disk5s1 [BLOCK] mount request: /dev/disk5s2 The volume remains unmounted. Interestingly, this also blocks: diskutil mount /dev/diskXsY because diskutil mount goes through Disk Arbitration. A direct filesystem mount such as mount_exfat, however, bypasses that approval request and can still be used to deliberately mount the filesystem read-only. Why this matters For an ordinary external disk, an unexpected automount may only be annoying. For data recovery, forensic inspection, or a failing disk, the difference can be important. If /etc/fstab says: ro I expect that policy to protect the source filesystem from writes. Silently mounting the filesystem read-write instead means that the volume becomes available to Finder and other background services. That is exactly what I am trying to avoid when working with a recovery source. For this reason, I would recommend verifying the actual mount state rather than assuming that an existing /etc/fstab ro entry is still protecting a disk after upgrading to Tahoe. For example: mount or: diskutil info /dev/diskXsY should be used to confirm the resulting state. Current workaround design I am currently using a small compatibility helper that treats /etc/fstab as the source of truth: /etc/fstab ↓ compatibility helper ↓ Disk Arbitration mount approval The daemon side handles mount policy before Disk Arbitration can automatically mount the volume. An explicit mount helper can then perform a direct filesystem mount with the options specified in /etc/fstab, including read-only mounting where required. The intention is not to replace /etc/fstab, but to restore the behavior that was previously provided by the system. Reproduction request If anyone else is running macOS Tahoe, I would be interested to know whether you can reproduce this with either: UUID= none apfs noauto or: UUID= none exfat noauto and similarly with ro. Please be careful when testing ro: use a disposable/test volume rather than a disk whose contents actually depend on remaining read-only. I have also submitted this to Apple through Feedback Assistant. Feedback ID: 24677522 I will update this post if Apple provides additional information or if a later Tahoe update changes the behavior.
Replies
1
Boosts
0
Views
287
Activity
1w
CarPlay custom symbols missing on iOS 27
We’re seeing custom symbol images disappear in CarPlay on iOS 27.0. Their text labels remain visible, and built-in SF Symbols still display correctly. We reproduced this in a small standalone app using: CPGridButton in CPListTemplate.headerGridButtons CPListImageRowItemCondensedElement The custom symbol is an SVG symbol asset loaded from a resource bundle: UIImage(named: "chapters", in: resourceBundle, compatibleWith: nil)?.withRenderingMode(.alwaysTemplate) For comparison, the same screen displays the built-in dot.radiowaves.left.and.right symbol. On iOS 26.6.1, the custom symbol and built-in symbol appear correctly in both controls. On iOS 27.0, the custom symbol is missing from both controls, while the built-in symbol remains visible. The failing device is an iPhone 13 Pro running iOS 27.0 (24A437), with the sample built using Xcode 27.0 (27A266a). Has anyone else encountered this? Is this a known regression, or is there a new requirement forsupplying custom symbols to CarPlay? Filed as FB24806621, with the standalone project and comparison photos.
Replies
1
Boosts
0
Views
172
Activity
1w
CallKit does not activate audio session with higher probability after upgrading to iOS 18.4.1
Hi, We've noticed that this issue occurs more frequently after upgrading to iOS 18.4.1 and can result in one-way audio. Our app uses CallKit with WebRTC to establish VoIP connections. However, on iOS 18.4.1, CallKit no longer triggers: func provider(_ provider: CXProvider, didActivate audioSession: AVAudioSession) We're currently comparing the occurrence rate across different iOS versions to better understand the impact. Could you please help analyze the root cause of this issue?
Replies
40
Boosts
1
Views
4.9k
Activity
1w
Does "Connectivity Assist" bypass NEPacketTunnelProvider DNS interception on iOS 27?
We have a NEPacketTunnelProvider extension that intercepts and modifies DNS responses for specific hostnames as part of its normal operation. On iOS 27, we are seeing this interception being intermittently bypassed. Our extension still receives the DNS query, builds a response, and returns it promptly, but the client occasionally proceeds using a different address, presumably the actual DNS resolution result. This behavior does not reproduce on iOS 26 or earlier. The timing in our logs appears to correlate with the new Connectivity Assist feature (Settings → Wi-Fi), which Apple describes as using cellular data alongside Wi-Fi to improve reliability. Our suspicion is that Connectivity Assist may be performing DNS resolution over a cellular path in parallel, outside the tunnel, causing that resolution path to bypass our provider entirely. We have ruled out response timing and response format issues on our side. Varying the speed and format of our responses does not affect the outcome, suggesting that the behavior is occurring at a layer above the tunnel provider. We have the following questions: Does Connectivity Assist perform DNS resolution on a network path that can bypass an active NEPacketTunnelProvider? Is there any API, entitlement, or supported mechanism to disable Connectivity Assist for an app, or to ensure that all DNS resolution is routed through the active tunnel, similar to previous Wi-Fi Assist opt-out capabilities? Would a NEDNSProxyProvider-based DNS proxy be affected in the same way, or does it operate at a layer that Connectivity Assist cannot bypass? Any guidance, references to relevant documentation, WWDC session content, or confirmation of the expected behavior would be greatly appreciated.
Replies
5
Boosts
0
Views
787
Activity
1w
Is DeviceActivitySchedule a supported way to wake an extension for periodic work?
I'm building a parental-control app using FamilyControls, ManagedSettings and DeviceActivity. A guardian can lock a child's device from their own device, and the child's device applies the shield locally. The delivery problem: a background push can't wake our app once it has been force-quit, which is common on a child's device, so guardian-initiated changes sit undelivered until the child happens to open the app. I've found that DeviceActivityMonitorExtension still receives intervalDidStart / intervalDidEnd while the app is force-quit, and that a URLSession request started from the extension completes. So I could register a couple of short recurring DeviceActivitySchedule activities purely to wake the extension every ~15 minutes, check the server, and apply the resulting shield. My question: is using DeviceActivitySchedule purely as a wake mechanism — where the schedule doesn't correspond to any real usage-monitoring window — a supported use of the API, or is it working by accident? I'd rather not build on it if it's the latter. Two smaller ones, if anyone knows: Is network activity from the monitor extension expected to be given time to complete, and is there a documented execution budget? I've seen reports here that the extension stops being invoked after some days without the host app launching. Is that expected, and what re-arms it? If there's a supported mechanism for this that I've missed, I'd much rather use it.
Replies
0
Boosts
0
Views
95
Activity
1w
StoreKit 2 currentEntitlements persists after Sandbox Purchase History reset in TestFlight
I am testing a StoreKit 2 non-consumable IAP through TestFlight. Product ID: com.metabolla.plus.lifetime Type: Non-Consumable Environment: TestFlight / Sandbox Transaction.currentEntitlements keeps returning an active entitlement for this product even after: configuring a Sandbox Apple Account clearing Sandbox Purchase History reinstalling the app rebooting the device Important detail: the first TestFlight purchase was completed before configuring the Sandbox Apple Account on the device. If I temporarily change the Product ID in code, the entitlement disappears, so the issue seems tied to the original Product ID/account/receipt. Question: Can a non-consumable TestFlight purchase made before Sandbox Apple Account configuration remain associated with the original TestFlight/Apple ID identity? Is there any supported way to clear this entitlement for testing?
Replies
5
Boosts
1
Views
1.4k
Activity
1w
Local notifications delayed by up to 5 seconds on iOS 27
When scheduling a local notification, it can be delayed by up to 5 seconds. On iOS 26, the notification appears instantly at the scheduled time. Feedback ID: FB23218437
Replies
3
Boosts
2
Views
1.2k
Activity
1w
Guideline 3.1.3(d) vs. EU External Purchase Link Entitlement — real-time one-to-many servic
Hello, We are the developers of UbiFit Go, a fitness marketplace app (Portugal/EU). We offer live, real-time group fitness classes via video call, purchased as a credit pack exclusively on our external website (Stripe), and consumed in-app via a native button — with no links, buttons, or WebViews pointing to our website inside the app (only static informational text, e.g. "manage your credits from your account on our website"). Guideline 3.1.3(d) states that "one-to-few and one-to-many real-time services must use in-app purchase." We would like to confirm: Does this static-text-only pattern (no in-app link of any kind) still fall under 3.1.3(d), or is it exempt because there is no purchase flow or redirection happening inside the app at all? If it does fall under 3.1.3(d), does the EU External Purchase Link Entitlement (per the Digital Markets Act) apply to real-time one-to-many services such as live group fitness classes, or is that entitlement limited to non-real-time digital goods? We want to ensure full compliance before implementing this feature. Thank you.
Replies
0
Boosts
0
Views
68
Activity
1w