Search results for

“sandbox”

10,540 results found

Post

Replies

Boosts

Views

Activity

Reply to App stuck "In Review" for 7 days after replying to a Guideline 2.1 information request
Since the Apple Pay button only appears when Wallet has an eligible card, the reviewer may not have been able to reach the payment sheet even with your navigation steps. I’d update the existing support case with the submission ID and ask App Review to confirm whether they opened the payment sheet, and, if not, what device, region, or Wallet setup they used. In the review notes, state the exact prerequisites for the button to appear and include a short recording of the flow. Also explain how the reviewer can inspect the rest of checkout if Apple Pay is unavailable on their device. Apple Pay sandbox testing requires a supported device, sandbox account, test card, and supported region, so verify that your own review walkthrough matches the intended review environment. Since the submission is still “In Review,” I would keep it active while asking for clarification rather than cancel it and start another cycle.
21m
StoreKit 2 assigned subscriptions: authenticating member enrollment into an application account
Our iPad application uses authenticated accounts in our own service. Before enabling access for a member receiving an assigned subscription, we need to establish that the actual assigned Apple member authorized enrollment into the intended account in our service. The unresolved case is another authenticated application account presenting forwarded, genuinely Apple-signed member transaction or app transaction evidence. We need to understand the supported verification boundary that prevents possession of that evidence from being sufficient to acquire another member's access. Personal purchase ownership will remain separate from assigned-member access. Proposed flow for review: The app obtains AppTransaction and the assigned Transaction directly from StoreKit and checks both against the current device using the documented device-verification procedure. It then proposes an App Attest assertion over the exact evidence and a server-issued challenge associated with the authenticated application account. The proposed
0
0
141
6h
ScreenCaptureKit is NOT a full replacement for CGWindowListCreateImage
My sandbox app on MAS (Hide Icons) simply toggles the visibility of the Desktop icons and Widgets on or off. It does this by display customized NSWindow on window level given by NSWindow.Level(rawValue: Int(CGWindowLevelForKey(.desktopIconWindow))+1) This custom NSWindow can either have a copy of the Desktop background/wallpaper CGImage or a solid color depending on user preference. Until macOS 27, this worked fine. To find all the Desktop background/wallpaper images (there can be multiple screens and each screen can have multiple Spaces), Apple provided code that avoided any TCC dialog boxes. Namely func getDesktopWindowIds() -> [CGWindowID] { let windows = CGWindowListCopyWindowInfo([.optionAll], kCGNullWindowID)! as! [[String: AnyObject]] let DesktopWindowLevel = CGWindowLevelForKey(.desktopWindow)-1 let DesktopWindows = windows.filter { let windowLevel = $0[kCGWindowLayer as String] as! CGWindowLevel return windowLevel == desktopWindowLevel } return desktopWindows.map { $0[kCGWindowNumber as S
2
0
346
12h
Reply to VZMacOSInstaller gave no completion callback before interruption; installation service logged socket sandbox denial and CSSM EPERM
[quote='908251022, vm_install_notes, /thread/849369?answerId=908251022#908251022, /profile/vm_install_notes'] specifically a sandbox-exec-based profile around the command runner [/quote] Yeah, I thought that might be the case. We don’t support custom sandboxes like this, for the reasons I described here. The nature of doing unsupported stuff is that you might encounter hard-to-explain problems. Sadly, that’s just how it is. You can continue down that path and try to work out what went wrong by yourself, but my advice is that you change your approach. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Topic: App & System Services SubTopic: Core OS Tags:
21h
In-App-Verification - PassKit
I am working on In-App-Verification. I am able to add my cards manually in the Apple Wallet Sandbox. I am getting the option to Verify using App. When I click on the Verify Button, I am able to redirect to my Testflight App. But when I use the API PKPassLibrary().pass(withPassTypeIdentifier: passTypeIdentifier, serialNumber: serialNumber) its not returning me the expected Pass. It is infact giving an empty result The entitlements which I already have added are: com.apple.developer.pass-type-identifiers com.apple.developer.payment-pass-provisioning So I have below questions: Do I need to do something else for PassKit API's to work? Is it even possible to test In-App-Verification in the TestFlight App using sandbox Wallet? Is it possible to redirect user to debug and enterprise builds also as currently the redirection from Apple Wallet is not working for debug and enterprise builds? The PassKit API which I indicated earlier is working in debug build when I sideload from Xcode. But since deepli
0
0
20
22h
In App Verification - PassKit
I am working on In-App-Verification. I am able to add my cards manually in the Apple Wallet Sandbox. I am getting the option to Verify using App. When I click on the Verify Button, I am able to redirect to my Testflight App. But when I use the API PKPassLibrary().pass(withPassTypeIdentifier: passTypeIdentifier, serialNumber: serialNumber) its not returning me the expected Pass. It is in-fact giving an empty result So I have below questions: Do I need to do something else for PassKit API's to work? Is it even possible to test In-App-Verification in the TestFlight App using sandbox Wallet?
0
0
10
22h
Reply to Questions on App Store Server API behaviors: Production accounts in Sandbox, and Cleared Sandbox data
Based on my research, I have formed the following understanding; is this correct? Regarding Case A (behavior when a purchase is made using a production account connected to Apple's Sandbox environment): ① What kind of account do reviewers use for testing? Reviewers use Apple's internal review devices and dedicated Apple accounts for review purposes. Although the build being reviewed is a production binary, StoreKit communication within the review environment is forcibly routed to the Sandbox environment by Apple's systems. The reviewers' accounts are configured within Apple's internal systems as special tester accounts authorized for Sandbox in-app purchase testing. ② Does StoreKit block this on the client side? It is not blocked. While regular users attempting to make a purchase using a production account in a development build would be rejected with a Not a Sandbox account error, Apple configures the system so that reviewer accounts successfully authenticate within the re
Topic: App & System Services SubTopic: StoreKit Tags:
1d
Reply to Is transactionId unique across Production and Sandbox environments for DB design?
Based on my research, I have arrived at the following conclusion; is my understanding correct? [Regarding potential transactionId collisions between Apple's Production and Sandbox environments] Uniqueness across environments: Global uniqueness across Production and Sandbox environments is not guaranteed. Suitability as a single primary key: Using transactionId alone as a primary key (PK) is not recommended. Recommended schema design: A composite key of (environment, transactionId), or a surrogate key combined with a composite unique constraint. Scope of uniqueness: According to Apple's specifications, transactionId is guaranteed to be unique within each specific environment (Production or Sandbox). However, since the Production and Sandbox environments operate as independent systems, the architectural possibility of the same numeric string being assigned—however rare—cannot be ruled out. Database design best practice: Adopting a composite key: In your table design, include
Topic: App & System Services SubTopic: StoreKit Tags:
2d
Reply to Title: Security-scoped folder bookmarks after rename or Trash: APFS vs exFAT/FAT32
Reading through your flow, this is what caught my eye: However, creating a bookmark using a URL reconstructed from that new pathname fails. If I understand this correctly, you retrieved the new path from your open file handle, then attempted to create a new URL to it, correct? If so, then that’s an invalid usage pattern that I wouldn't trust to be reliable. You can use the same logic to detect that the directory has moved, but then do the following: Resolve your existing bookmark, checking isStale==true (it will be stale, but this is a good sanity check). If resolution succeeds, generate a new bookmark using the URL you just resolved. Does that flow work? Moving to other details: Relaunch: the app reports the folder as unavailable. What does this mean at an API level? Is bookmark resolution failing or something else? We also encountered failures when inspecting the Trash relationship using FileManager.getRelationship(_:of:in:toItemAt:) with .trashDirectory. Can you be more specific about this? There are defin
Topic: App & System Services SubTopic: Core OS Tags:
2d
NSOSStatusErrorDomain/-26276 during Code Signing trust evaluation and strict verification
I am diagnosing a trust failure for an archived iOS arm64 app, without changing trust settings or rebuilding speculatively. Environment: macOS 26.6.2 (25G83), Xcode 27.0 (27A266a), as reported by installed public metadata. The diagnostic is a non-interactive Python helper calling the installed Security/CoreFoundation APIs through a bounded child-process runner in a desktop coding-agent session. This is not an Xcode GUI operation; an effect of the session, keychain/cache, or service access has not been established. Observed results: The app's embedded code CMS supplies three certificates. One explicitly identified signer matches the stored signer receipt in memory. The helper places the signer first, followed by the other supplied certificates. It uses SecPolicyCreateWithProperties(kSecPolicyAppleCodeSigning), SecTrustCreateWithCertificates, and SecTrustSetNetworkFetchAllowed(false). The status-returning setup calls succeed. Disabling intermediate fetching does not prove that all OS revocation/cache/network ac
4
0
864
2d
Reply to VZMacOSInstaller gave no completion callback before interruption; installation service logged socket sandbox denial and CSSM EPERM
[quote='849369021, vm_install_notes, /thread/849369, /profile/vm_install_notes'] a host-only connection succeeded outside the command sandbox. [/quote] I’d like to clarify what you mean by this. Specifically, what is this “command sandbox”? Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Topic: App & System Services SubTopic: Core OS Tags:
2d
Reply to Title: Security-scoped folder bookmarks after rename or Trash: APFS vs exFAT/FAT32
The concern is how frequently that recovery becomes necessary. In our tests, an ordinary external folder rename reproduces the problem on FAT32/exFAT, while the same workflow appears to work on APFS. If it was me, then I wouldn't worry about it. Foreign file systems are always problematic. While the app remains running, its existing file descriptor still tracks the renamed folder. On exFAT, we traced creation of the replacement security-scoped bookmark to an open() failure with EPERM. Reselecting that same folder through the system picker allows bookmark creation and subsequent access after relaunch. Two questions: What are you doing with this folder? It sounds like you're keeping a file descriptor open on it for a long time. That's risky. Ideally, you're going to wrap each access in a file coordination block. In theory, that should guard against some level of external manipulation. Are you doing that? (Note: my own file coordination experience is strictly theoretical. I've never seen it do anything really.)
Topic: App & System Services SubTopic: Core OS Tags:
3d
Reply to Title: Security-scoped folder bookmarks after rename or Trash: APFS vs exFAT/FAT32
Thanks. We already implemented explicit reselection as a recovery path, and confirmed that it restores access after relaunch. The concern is how frequently that recovery becomes necessary. In our tests, an ordinary external folder rename reproduces the problem on FAT32/exFAT, while the same workflow appears to work on APFS. While the app remains running, its existing file descriptor still tracks the renamed folder. On exFAT, we traced creation of the replacement security-scoped bookmark to an open() failure with EPERM. Reselecting that same folder through the system picker allows bookmark creation and subsequent access after relaunch. Saving the last known URL could help guide the user through recovery, but would not itself restore authorization or establish that a folder subsequently found at that path is the original resource. We agree that bookmark failures need a recovery path. The remaining question is whether repeated reselection after ordinary renames is unavoidable under these constraints: a sandboxed
Topic: App & System Services SubTopic: Core OS Tags:
3d
Title: Security-scoped folder bookmarks after rename or Trash: APFS vs exFAT/FAT32
I’m developing a sandboxed macOS app that needs persistent, read-only access to a user-selected folder. We are observing different behaviour between APFS and FAT32/exFAT after renaming the folder or moving it to Trash. The main problem is that the app can still track the folder while running, but cannot reliably restore the connection or identify its location after relaunch. Environment macOS 27.0.1 (26A434) Xcode 27.1 (27A9269) App Sandbox and user-selected file access enabled Folder selection through SwiftUI fileImporter Bookmark creation: .withSecurityScope and .securityScopeAllowOnlyReadAccess Bookmark resolution: .withSecurityScope The selected items are ordinary folders, not volume roots. Filesystem comparison APFS: the tested workflows appear to work as expected, including restoration after relaunch. exFAT: we have reproduced both bookmark renewal failure after a rename and loss of the “in Trash” classification after relaunch. FAT32: we have observed automatic bookmark renewal failure
4
0
157
3d
Xcode 26.6: supported diagnostics for project-loader exit 74 under a restricted sandbox
On macOS 26.6 (25G72), Xcode 26.6 (17F113), xcodebuild -showBuildSettings -json exits naturally with code 74 and reports that the project cannot be read / does not exist. Minimal control: A synthetic three-file .xcodeproj with one iOS application target, one shared scheme and an internal workspace. It contains no app source, package dependencies, extensions or build scripts. Its plist/XML and object references passed static validation. This does not establish that Xcode accepts the project. Reproduction outline: Run xcodebuild for this control under a custom sandbox-exec profile, with a clean environment, isolated HOME/cache/DerivedData, Release configuration, iphoneos SDK, generic/platform=iOS, automatic package resolution disabled, signing disabled, and -showBuildSettings -json. No build or device operation is requested. The profile keeps the control project read-only, restricts access to protected host data, and denies network and Simulator/device services. The exact profile is not attached to thi
0
0
85
3d
Reply to App stuck "In Review" for 7 days after replying to a Guideline 2.1 information request
Since the Apple Pay button only appears when Wallet has an eligible card, the reviewer may not have been able to reach the payment sheet even with your navigation steps. I’d update the existing support case with the submission ID and ask App Review to confirm whether they opened the payment sheet, and, if not, what device, region, or Wallet setup they used. In the review notes, state the exact prerequisites for the button to appear and include a short recording of the flow. Also explain how the reviewer can inspect the rest of checkout if Apple Pay is unavailable on their device. Apple Pay sandbox testing requires a supported device, sandbox account, test card, and supported region, so verify that your own review walkthrough matches the intended review environment. Since the submission is still “In Review,” I would keep it active while asking for clarification rather than cancel it and start another cycle.
Replies
Boosts
Views
Activity
21m
StoreKit 2 assigned subscriptions: authenticating member enrollment into an application account
Our iPad application uses authenticated accounts in our own service. Before enabling access for a member receiving an assigned subscription, we need to establish that the actual assigned Apple member authorized enrollment into the intended account in our service. The unresolved case is another authenticated application account presenting forwarded, genuinely Apple-signed member transaction or app transaction evidence. We need to understand the supported verification boundary that prevents possession of that evidence from being sufficient to acquire another member's access. Personal purchase ownership will remain separate from assigned-member access. Proposed flow for review: The app obtains AppTransaction and the assigned Transaction directly from StoreKit and checks both against the current device using the documented device-verification procedure. It then proposes an App Attest assertion over the exact evidence and a server-issued challenge associated with the authenticated application account. The proposed
Replies
0
Boosts
0
Views
141
Activity
6h
ScreenCaptureKit is NOT a full replacement for CGWindowListCreateImage
My sandbox app on MAS (Hide Icons) simply toggles the visibility of the Desktop icons and Widgets on or off. It does this by display customized NSWindow on window level given by NSWindow.Level(rawValue: Int(CGWindowLevelForKey(.desktopIconWindow))+1) This custom NSWindow can either have a copy of the Desktop background/wallpaper CGImage or a solid color depending on user preference. Until macOS 27, this worked fine. To find all the Desktop background/wallpaper images (there can be multiple screens and each screen can have multiple Spaces), Apple provided code that avoided any TCC dialog boxes. Namely func getDesktopWindowIds() -> [CGWindowID] { let windows = CGWindowListCopyWindowInfo([.optionAll], kCGNullWindowID)! as! [[String: AnyObject]] let DesktopWindowLevel = CGWindowLevelForKey(.desktopWindow)-1 let DesktopWindows = windows.filter { let windowLevel = $0[kCGWindowLayer as String] as! CGWindowLevel return windowLevel == desktopWindowLevel } return desktopWindows.map { $0[kCGWindowNumber as S
Replies
2
Boosts
0
Views
346
Activity
12h
Reply to VZMacOSInstaller gave no completion callback before interruption; installation service logged socket sandbox denial and CSSM EPERM
[quote='908251022, vm_install_notes, /thread/849369?answerId=908251022#908251022, /profile/vm_install_notes'] specifically a sandbox-exec-based profile around the command runner [/quote] Yeah, I thought that might be the case. We don’t support custom sandboxes like this, for the reasons I described here. The nature of doing unsupported stuff is that you might encounter hard-to-explain problems. Sadly, that’s just how it is. You can continue down that path and try to work out what went wrong by yourself, but my advice is that you change your approach. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
21h
In-App-Verification - PassKit
I am working on In-App-Verification. I am able to add my cards manually in the Apple Wallet Sandbox. I am getting the option to Verify using App. When I click on the Verify Button, I am able to redirect to my Testflight App. But when I use the API PKPassLibrary().pass(withPassTypeIdentifier: passTypeIdentifier, serialNumber: serialNumber) its not returning me the expected Pass. It is infact giving an empty result The entitlements which I already have added are: com.apple.developer.pass-type-identifiers com.apple.developer.payment-pass-provisioning So I have below questions: Do I need to do something else for PassKit API's to work? Is it even possible to test In-App-Verification in the TestFlight App using sandbox Wallet? Is it possible to redirect user to debug and enterprise builds also as currently the redirection from Apple Wallet is not working for debug and enterprise builds? The PassKit API which I indicated earlier is working in debug build when I sideload from Xcode. But since deepli
Replies
0
Boosts
0
Views
20
Activity
22h
In App Verification - PassKit
I am working on In-App-Verification. I am able to add my cards manually in the Apple Wallet Sandbox. I am getting the option to Verify using App. When I click on the Verify Button, I am able to redirect to my Testflight App. But when I use the API PKPassLibrary().pass(withPassTypeIdentifier: passTypeIdentifier, serialNumber: serialNumber) its not returning me the expected Pass. It is in-fact giving an empty result So I have below questions: Do I need to do something else for PassKit API's to work? Is it even possible to test In-App-Verification in the TestFlight App using sandbox Wallet?
Replies
0
Boosts
0
Views
10
Activity
22h
Reply to Questions on App Store Server API behaviors: Production accounts in Sandbox, and Cleared Sandbox data
Based on my research, I have formed the following understanding; is this correct? Regarding Case A (behavior when a purchase is made using a production account connected to Apple's Sandbox environment): ① What kind of account do reviewers use for testing? Reviewers use Apple's internal review devices and dedicated Apple accounts for review purposes. Although the build being reviewed is a production binary, StoreKit communication within the review environment is forcibly routed to the Sandbox environment by Apple's systems. The reviewers' accounts are configured within Apple's internal systems as special tester accounts authorized for Sandbox in-app purchase testing. ② Does StoreKit block this on the client side? It is not blocked. While regular users attempting to make a purchase using a production account in a development build would be rejected with a Not a Sandbox account error, Apple configures the system so that reviewer accounts successfully authenticate within the re
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
1d
Reply to Is transactionId unique across Production and Sandbox environments for DB design?
Based on my research, I have arrived at the following conclusion; is my understanding correct? [Regarding potential transactionId collisions between Apple's Production and Sandbox environments] Uniqueness across environments: Global uniqueness across Production and Sandbox environments is not guaranteed. Suitability as a single primary key: Using transactionId alone as a primary key (PK) is not recommended. Recommended schema design: A composite key of (environment, transactionId), or a surrogate key combined with a composite unique constraint. Scope of uniqueness: According to Apple's specifications, transactionId is guaranteed to be unique within each specific environment (Production or Sandbox). However, since the Production and Sandbox environments operate as independent systems, the architectural possibility of the same numeric string being assigned—however rare—cannot be ruled out. Database design best practice: Adopting a composite key: In your table design, include
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
2d
Reply to Title: Security-scoped folder bookmarks after rename or Trash: APFS vs exFAT/FAT32
Reading through your flow, this is what caught my eye: However, creating a bookmark using a URL reconstructed from that new pathname fails. If I understand this correctly, you retrieved the new path from your open file handle, then attempted to create a new URL to it, correct? If so, then that’s an invalid usage pattern that I wouldn't trust to be reliable. You can use the same logic to detect that the directory has moved, but then do the following: Resolve your existing bookmark, checking isStale==true (it will be stale, but this is a good sanity check). If resolution succeeds, generate a new bookmark using the URL you just resolved. Does that flow work? Moving to other details: Relaunch: the app reports the folder as unavailable. What does this mean at an API level? Is bookmark resolution failing or something else? We also encountered failures when inspecting the Trash relationship using FileManager.getRelationship(_:of:in:toItemAt:) with .trashDirectory. Can you be more specific about this? There are defin
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
2d
NSOSStatusErrorDomain/-26276 during Code Signing trust evaluation and strict verification
I am diagnosing a trust failure for an archived iOS arm64 app, without changing trust settings or rebuilding speculatively. Environment: macOS 26.6.2 (25G83), Xcode 27.0 (27A266a), as reported by installed public metadata. The diagnostic is a non-interactive Python helper calling the installed Security/CoreFoundation APIs through a bounded child-process runner in a desktop coding-agent session. This is not an Xcode GUI operation; an effect of the session, keychain/cache, or service access has not been established. Observed results: The app's embedded code CMS supplies three certificates. One explicitly identified signer matches the stored signer receipt in memory. The helper places the signer first, followed by the other supplied certificates. It uses SecPolicyCreateWithProperties(kSecPolicyAppleCodeSigning), SecTrustCreateWithCertificates, and SecTrustSetNetworkFetchAllowed(false). The status-returning setup calls succeed. Disabling intermediate fetching does not prove that all OS revocation/cache/network ac
Replies
4
Boosts
0
Views
864
Activity
2d
Reply to VZMacOSInstaller gave no completion callback before interruption; installation service logged socket sandbox denial and CSSM EPERM
[quote='849369021, vm_install_notes, /thread/849369, /profile/vm_install_notes'] a host-only connection succeeded outside the command sandbox. [/quote] I’d like to clarify what you mean by this. Specifically, what is this “command sandbox”? Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
2d
Reply to Title: Security-scoped folder bookmarks after rename or Trash: APFS vs exFAT/FAT32
The concern is how frequently that recovery becomes necessary. In our tests, an ordinary external folder rename reproduces the problem on FAT32/exFAT, while the same workflow appears to work on APFS. If it was me, then I wouldn't worry about it. Foreign file systems are always problematic. While the app remains running, its existing file descriptor still tracks the renamed folder. On exFAT, we traced creation of the replacement security-scoped bookmark to an open() failure with EPERM. Reselecting that same folder through the system picker allows bookmark creation and subsequent access after relaunch. Two questions: What are you doing with this folder? It sounds like you're keeping a file descriptor open on it for a long time. That's risky. Ideally, you're going to wrap each access in a file coordination block. In theory, that should guard against some level of external manipulation. Are you doing that? (Note: my own file coordination experience is strictly theoretical. I've never seen it do anything really.)
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
3d
Reply to Title: Security-scoped folder bookmarks after rename or Trash: APFS vs exFAT/FAT32
Thanks. We already implemented explicit reselection as a recovery path, and confirmed that it restores access after relaunch. The concern is how frequently that recovery becomes necessary. In our tests, an ordinary external folder rename reproduces the problem on FAT32/exFAT, while the same workflow appears to work on APFS. While the app remains running, its existing file descriptor still tracks the renamed folder. On exFAT, we traced creation of the replacement security-scoped bookmark to an open() failure with EPERM. Reselecting that same folder through the system picker allows bookmark creation and subsequent access after relaunch. Saving the last known URL could help guide the user through recovery, but would not itself restore authorization or establish that a folder subsequently found at that path is the original resource. We agree that bookmark failures need a recovery path. The remaining question is whether repeated reselection after ordinary renames is unavoidable under these constraints: a sandboxed
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
3d
Title: Security-scoped folder bookmarks after rename or Trash: APFS vs exFAT/FAT32
I’m developing a sandboxed macOS app that needs persistent, read-only access to a user-selected folder. We are observing different behaviour between APFS and FAT32/exFAT after renaming the folder or moving it to Trash. The main problem is that the app can still track the folder while running, but cannot reliably restore the connection or identify its location after relaunch. Environment macOS 27.0.1 (26A434) Xcode 27.1 (27A9269) App Sandbox and user-selected file access enabled Folder selection through SwiftUI fileImporter Bookmark creation: .withSecurityScope and .securityScopeAllowOnlyReadAccess Bookmark resolution: .withSecurityScope The selected items are ordinary folders, not volume roots. Filesystem comparison APFS: the tested workflows appear to work as expected, including restoration after relaunch. exFAT: we have reproduced both bookmark renewal failure after a rename and loss of the “in Trash” classification after relaunch. FAT32: we have observed automatic bookmark renewal failure
Replies
4
Boosts
0
Views
157
Activity
3d
Xcode 26.6: supported diagnostics for project-loader exit 74 under a restricted sandbox
On macOS 26.6 (25G72), Xcode 26.6 (17F113), xcodebuild -showBuildSettings -json exits naturally with code 74 and reports that the project cannot be read / does not exist. Minimal control: A synthetic three-file .xcodeproj with one iOS application target, one shared scheme and an internal workspace. It contains no app source, package dependencies, extensions or build scripts. Its plist/XML and object references passed static validation. This does not establish that Xcode accepts the project. Reproduction outline: Run xcodebuild for this control under a custom sandbox-exec profile, with a clean environment, isolated HOME/cache/DerivedData, Release configuration, iphoneos SDK, generic/platform=iOS, automatic package resolution disabled, signing disabled, and -showBuildSettings -json. No build or device operation is requested. The profile keeps the control project read-only, restricts access to protected host data, and denies network and Simulator/device services. The exact profile is not attached to thi
Replies
0
Boosts
0
Views
85
Activity
3d