Search results for

“sandbox”

10,540 results found

Post

Replies

Boosts

Views

Activity

Reply to Product.products(for:) returns wrong storefront/currency on TestFlight while purchase sheet resolves correctly
Update with a decisive data point: I ran a real (non-cancelled) sandbox purchase through the minimal repro project. The resulting Transaction.storefrontCountryCode = GBR and Transaction.currency = GBP — correct. But Storefront.current, called immediately after and again 3 seconds later in the same process, still returns countryCode USA, id 143444. This shows StoreKit has the correct storefront information available (it used it to process the transaction correctly) but Storefront.current and the product catalog query are not returning it. This looks like an internal inconsistency between StoreKit's transaction-processing path and its storefront-reporting API, not an account or device configuration issue.
Topic: App & System Services SubTopic: StoreKit Tags:
Aug ’26
Reply to Guideline 4.3(a): 5 rejections despite major code and content changes
Different from what ? Does it mean that at first there was effectively a problem ? By different I meant different from my previous game and other similar games. I only started explaining that after reading advice from other developers who got 4.3. As for the category it’s already games with simulation and racing as the subcategories. I honestly don’t see what else would even make sense. And I don’t really think this niche is that saturated compared to some others. I can only find around 3 real sandbox car crash games that are actually similar, not counting my older game
Aug ’26
Guideline 4.3(a): 5 rejections despite major code and content changes
Hi everyone. I’m looking for some advice regarding repeated rejections under Guideline 4.3(a) - Design - Spam. I’m a solo developer and have been making car simulator sandbox games since 2020. I already have an older game in the same genre on the App Store, and I’ve spent around 2 years developing its sequel. The new game is also available on Google Play, where it has passed 1M installs in its first month and currently has a 4.9 rating. The iOS version has now been rejected 5 times over the last 4 months. Attempt 1: Rejected under 4.3(a) with: We noticed the app shares a similar binary, metadata, and/or concept... I explained what makes the game different, filed an appeal, added a new feature, and submitted again. Attempt 2: Same rejection. I requested a phone call with App Review. During the call, I was told that their system had detected a binary match with another developer’s game in the same genre. The reviewer explained that similarities could come from game code, assets, shared engine code, ad
4
0
588
Aug ’26
Reply to Is it possible to intercept hardware (Bluetooth) keyboard events in an iOS Custom Keyboard Extension?
The channel is probably encrypted. If it is not, then just write a bluetooth driver, I don't think that the way you are doing it is enough to intercept a modern bluetooth link. At least not the kind of links we have in my country... Sandbox does not block bluetooth. Sandbox does not block kernel extensions. Go to the library and pick up a book if you can't find online, regular pentesting is crucial to even try to maintain your posture in today's world. Just stop speculating and start executing.
Topic: UI Frameworks SubTopic: UIKit Tags:
Aug ’26
Sandboxed macOS app using SwiftData and CloudKit cannot initialize CloudKit mirroring.
I have a Mac and iOS app intended to sync data in iCloud. Both apps in TestFlight, the iOS reads and writes to iCloud but the Mac fails as the App Sandbox denies mach-lookup com.apple.cloudd, so NSCloudKitMirroringDelegate` never reaches the daemon and setup fails permanently. I have a minimal app reproducing the issue on for the Mac app. I also submitted a feedback FB24450529
1
0
593
Aug ’26
Reply to Access to user’s application usage
Thanks for the post. For privacy considerations and sandboxing rules strictly prohibit apps from directly accessing raw application usage data or Screen Time statistics for other apps. You cannot get a readable list of which apps a user has installed or exactly how much time they spend on each specific app. However, the Screen Time API (introduced in iOS 15), which allows developers to build parental control and digital wellbeing apps. This API consists of three frameworks: FamilyControls, ManagedSettings, and DeviceActivity. If you'd like us to consider adding the necessary functionality, please file an enhancement request using Feedback Assistant. Once you file the request, please post the FB number here. If you're not familiar with how to file enhancement requests, take a look at Bug Reporting: How and Why? Albert  WWDR
Topic: App & System Services SubTopic: General Tags:
Aug ’26
Production APNs rejects a valid production device token with BadEnvironmentKeyInToken (newly released app)
My app was approved and released on the App Store on Aug 19, 2026 (bundle ID br.com.stackads.app, Team ID MSGM29Z362). Push notifications do not work on the production/App Store/TestFlight build. Android via FCM works fine; only iOS production APNs fails. It has been more than 48 hours since release. I captured the raw APNs device token directly from application(_:didRegisterForRemoteNotificationsWithDeviceToken:) in a production (App Store distribution) build (aps-environment = production, verified in the built .ipa entitlements). Sending directly to APNs with a token-based .p8 auth key (Key ID VXXXXXXX, Team ID MSGM29Z362), apns-topic br.com.stackads.app, apns-push-type alert, returns: api.push.apple.com (production): HTTP 403 {reason:BadEnvironmentKeyInToken} api.sandbox.push.apple.com (sandbox): HTTP 400 {reason:BadDeviceToken} The provider (JWT) authentication succeeds (I get a device-token error, not an auth error), so the key is valid. The App ID has the Push Notifications capability enabled.
0
0
369
Aug ’26
How can a watchOS-only app submit its first IAP when App Store Connect blocks it?
I’m trying to determine the supported submission path for the first non-consumable IAP in a watchOS-only app. Configuration The app uses a standard watch-only container: Container: com.seanfu.safe Watch app: com.seanfu.safe.watchkitapp ITSWatchOnlyContainer = true WKWatchOnly = true WKApplication = true It offers one non-consumable “Full Version” unlock and uses StoreKit 2: Product.products(for:) Product.purchase(options:) Transaction.currentEntitlements Transaction.updates The product ID in the Release binary exactly matches App Store Connect. Paid Apps agreements, banking, tax, pricing, and territory availability are active. The Release archive contains no local .storekit configuration or test bundle. TestFlight works, but App Review receives no product In TestFlight, using the real App Store sandbox and App Store Connect product configuration, Product.products(for:) returns the correct product, localized price, and title. The purchase sheet can be presented. During App Review, the same request rep
1
0
592
Aug ’26
Is it possible to intercept hardware (Bluetooth) keyboard events in an iOS Custom Keyboard Extension?
I'm developing an iOS custom keyboard extension and need to intercept external Bluetooth hardware keystrokes in the background. Can I capture these events within a UIInputViewController (e.g., using UIKeyCommand), or does iOS strictly route them directly to the host app? Are there any specific APIs or workarounds for this, or is it completely blocked by Apple's sandboxing policies?
1
0
657
Aug ’26
Reply to SFAuthorizationPluginView UI changes in macOS Golden Gate Beta – Unable to access the child elements and button controls using NSAccessibilityProtocol
Thanks for filing FB24412830. [quote='902166022, PrathibhaD, /thread/842397?answerId=902166022#902166022, /profile/PrathibhaD'] As this worked upto Tahoe … [/quote] Right, but that’s only because it was relying on implementation details. We don’t support folks navigating the view hierarchy in order to manipulate system views. So, when you ask about “intentional change” you need to consider what actually changed. The supported API hasn’t changed here. Rather, we’ve changed a bunch of implementation details. Was that intentional? Clearly. Was the intention to break your product? Probably not (although it’s not like I’d admit that if it were :-). My best guess is that these views have moved to a different process. Way back in the day macOS gained support for remote views, that is, a view that looks like it’s in an app’s window but is actually hosted in a completely different process. The canonical example of this is Powerbox, where we host the standard file open and save views in a separate process so that they
Topic: Privacy & Security SubTopic: General Tags:
Aug ’26
Reply to Sandbox denies mach-lookup com.apple.cloudd only when app is launched outside Xcode (CKError 6)
That fixed it. Thank you — and thank you for pushing me back to the recommended answer in the referenced thread. I had read the thread but missed that workaround entirely. For anyone finding this later, here is what my case looked like: My app uses CloudKit only indirectly, through NSPersistentCloudKitContainer. It never references a single CloudKit symbol of its own. So the framework was not loaded at launch, the sandbox came up without the iCloud exception, and the kernel denied com.apple.cloudd and com.apple.duetactivityscheduler — resulting in CKError 6 on every launch that did not come from Xcode. Launched by Xcode it always worked, which is what kept me looking in the wrong place. Adding a line that touches CloudKit at the very start of the launch path was enough. Everything else I had compared between a working app of mine and this one — entitlements and their values, embedded profiles and the entitlements they grant, provisioned devices, signing identity, Designated Requirement, quarantine, b
Topic: App & System Services SubTopic: iCloud Tags:
Aug ’26
How can a local AI agent use MLX/Metal unattended on macOS while remaining confined to an authorized workspace?
How can a local AI agent use MLX/Metal unattended while remaining confined to an authorized workspace? I am developing an AI-driven local media-processing workflow on an Apple-silicon Mac and am trying to understand the correct architecture for allowing it to run unattended without giving the AI agent unrestricted access to my primary personal computer. I am not a software engineer, so I may be missing an established macOS mechanism or using the wrong terminology. I would appreciate guidance from people familiar with MLX, Metal, sandboxing, and macOS security. What I am building I use OpenAI Codex as the local execution/software-development agent. The working system currently: ingests and verifies original video and still media while preserving immutable originals; performs visual semantic analysis and divides video into meaningful time-coded segments; separately analyzes spoken language rather than assuming audio and video are semantically equivalent; uses MLX Whisper locally on Apple silicon for ti
0
0
694
Aug ’26
Reply to Sandbox denies mach-lookup com.apple.cloudd only when app is launched outside Xcode (CKError 6)
Thanks for the pointer. That thread shows the same two sandbox denials, but the case there is a Store profile. Mine is a development profile, so I ran a controlled comparison of two of my own apps on one machine. The result is a contradiction I cannot explain, and I would appreciate guidance. Setup macOS 26.6.1, Xcode 26.6. Sandboxed macOS app, Core Data with NSPersistentCloudKitContainer, automatic signing, Apple Development certificate, Xcode-managed Mac Team Provisioning Profile. Symptom CloudKit fails with CKErrorDomain Code=6 whenever the app is launched by anything other than Xcode. The kernel logs: Sandbox: NoteManagerPro(44046) deny(1) mach-lookup com.apple.duetactivityscheduler Sandbox: NoteManagerPro(44046) deny(1) mach-lookup com.apple.cloudd Launched by Xcode, the same bundle works perfectly: the profile is evaluated, TCC approves the container, and there is real traffic to gateway.icloud.com with no errors. The control case A second app of mine on the same Mac,
Topic: App & System Services SubTopic: iCloud Tags:
Aug ’26
Reply to Transaction.finish() is a no-op on iOS 27 beta 5; purchase() then replays the same transaction forever
Also reproduces on StoreKit 1 — with daemon logs and server-side confirmation Same behaviour here through a different API. We use StoreKit 1 (SKPaymentQueue.finishTransaction:), not StoreKit 2, so the defect looks like it sits below both API surfaces. Device iPhone 17 Pro, iOS 27.0 from Aug 14, sandbox account, consumables. Transactions survive their own finish, are redelivered on every launch, and repeat buys replay the same transaction id with no sheet and no charge. We had a device log running, so here is where it fails — 8 finish attempts in the capture, 8 identical failures, 0 successes: storekitd [7ae43896_SK1] Starting request FinishTransactionRequest (accountRequirement: required(signIn: false, …), client: eu.nordeus.TopEleven Sandbox, destination: AMSBagKey(p2-in-app-transaction-done), …) storekitd [7ae43896_SK1] Account is required for request. error [7ae43896_SK1] Failed to encode request parameters (Never): Error Domain=NSCocoaErrorDomain Code=3840 JSON text did not start with ar
Topic: App & System Services SubTopic: StoreKit Tags:
Aug ’26
Reply to Unable to enable eligibility for External Purchase Link APIs — seeking clarification
Exact same issue as helong here - ensured both my prod account and sandbox account are set to Ireland and that ie is in my list of customlinkregions with no luck. Country detected correctly and I even get a warning about external purchases, but isEligible is always false.
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Aug ’26
Reply to Product.products(for:) returns wrong storefront/currency on TestFlight while purchase sheet resolves correctly
Update with a decisive data point: I ran a real (non-cancelled) sandbox purchase through the minimal repro project. The resulting Transaction.storefrontCountryCode = GBR and Transaction.currency = GBP — correct. But Storefront.current, called immediately after and again 3 seconds later in the same process, still returns countryCode USA, id 143444. This shows StoreKit has the correct storefront information available (it used it to process the transaction correctly) but Storefront.current and the product catalog query are not returning it. This looks like an internal inconsistency between StoreKit's transaction-processing path and its storefront-reporting API, not an account or device configuration issue.
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Aug ’26
Reply to Guideline 4.3(a): 5 rejections despite major code and content changes
Different from what ? Does it mean that at first there was effectively a problem ? By different I meant different from my previous game and other similar games. I only started explaining that after reading advice from other developers who got 4.3. As for the category it’s already games with simulation and racing as the subcategories. I honestly don’t see what else would even make sense. And I don’t really think this niche is that saturated compared to some others. I can only find around 3 real sandbox car crash games that are actually similar, not counting my older game
Replies
Boosts
Views
Activity
Aug ’26
Guideline 4.3(a): 5 rejections despite major code and content changes
Hi everyone. I’m looking for some advice regarding repeated rejections under Guideline 4.3(a) - Design - Spam. I’m a solo developer and have been making car simulator sandbox games since 2020. I already have an older game in the same genre on the App Store, and I’ve spent around 2 years developing its sequel. The new game is also available on Google Play, where it has passed 1M installs in its first month and currently has a 4.9 rating. The iOS version has now been rejected 5 times over the last 4 months. Attempt 1: Rejected under 4.3(a) with: We noticed the app shares a similar binary, metadata, and/or concept... I explained what makes the game different, filed an appeal, added a new feature, and submitted again. Attempt 2: Same rejection. I requested a phone call with App Review. During the call, I was told that their system had detected a binary match with another developer’s game in the same genre. The reviewer explained that similarities could come from game code, assets, shared engine code, ad
Replies
4
Boosts
0
Views
588
Activity
Aug ’26
Reply to Is it possible to intercept hardware (Bluetooth) keyboard events in an iOS Custom Keyboard Extension?
The channel is probably encrypted. If it is not, then just write a bluetooth driver, I don't think that the way you are doing it is enough to intercept a modern bluetooth link. At least not the kind of links we have in my country... Sandbox does not block bluetooth. Sandbox does not block kernel extensions. Go to the library and pick up a book if you can't find online, regular pentesting is crucial to even try to maintain your posture in today's world. Just stop speculating and start executing.
Topic: UI Frameworks SubTopic: UIKit Tags:
Replies
Boosts
Views
Activity
Aug ’26
Sandboxed macOS app using SwiftData and CloudKit cannot initialize CloudKit mirroring.
I have a Mac and iOS app intended to sync data in iCloud. Both apps in TestFlight, the iOS reads and writes to iCloud but the Mac fails as the App Sandbox denies mach-lookup com.apple.cloudd, so NSCloudKitMirroringDelegate` never reaches the daemon and setup fails permanently. I have a minimal app reproducing the issue on for the Mac app. I also submitted a feedback FB24450529
Replies
1
Boosts
0
Views
593
Activity
Aug ’26
Reply to Access to user’s application usage
Thanks for the post. For privacy considerations and sandboxing rules strictly prohibit apps from directly accessing raw application usage data or Screen Time statistics for other apps. You cannot get a readable list of which apps a user has installed or exactly how much time they spend on each specific app. However, the Screen Time API (introduced in iOS 15), which allows developers to build parental control and digital wellbeing apps. This API consists of three frameworks: FamilyControls, ManagedSettings, and DeviceActivity. If you'd like us to consider adding the necessary functionality, please file an enhancement request using Feedback Assistant. Once you file the request, please post the FB number here. If you're not familiar with how to file enhancement requests, take a look at Bug Reporting: How and Why? Albert  WWDR
Topic: App & System Services SubTopic: General Tags:
Replies
Boosts
Views
Activity
Aug ’26
Production APNs rejects a valid production device token with BadEnvironmentKeyInToken (newly released app)
My app was approved and released on the App Store on Aug 19, 2026 (bundle ID br.com.stackads.app, Team ID MSGM29Z362). Push notifications do not work on the production/App Store/TestFlight build. Android via FCM works fine; only iOS production APNs fails. It has been more than 48 hours since release. I captured the raw APNs device token directly from application(_:didRegisterForRemoteNotificationsWithDeviceToken:) in a production (App Store distribution) build (aps-environment = production, verified in the built .ipa entitlements). Sending directly to APNs with a token-based .p8 auth key (Key ID VXXXXXXX, Team ID MSGM29Z362), apns-topic br.com.stackads.app, apns-push-type alert, returns: api.push.apple.com (production): HTTP 403 {reason:BadEnvironmentKeyInToken} api.sandbox.push.apple.com (sandbox): HTTP 400 {reason:BadDeviceToken} The provider (JWT) authentication succeeds (I get a device-token error, not an auth error), so the key is valid. The App ID has the Push Notifications capability enabled.
Replies
0
Boosts
0
Views
369
Activity
Aug ’26
How can a watchOS-only app submit its first IAP when App Store Connect blocks it?
I’m trying to determine the supported submission path for the first non-consumable IAP in a watchOS-only app. Configuration The app uses a standard watch-only container: Container: com.seanfu.safe Watch app: com.seanfu.safe.watchkitapp ITSWatchOnlyContainer = true WKWatchOnly = true WKApplication = true It offers one non-consumable “Full Version” unlock and uses StoreKit 2: Product.products(for:) Product.purchase(options:) Transaction.currentEntitlements Transaction.updates The product ID in the Release binary exactly matches App Store Connect. Paid Apps agreements, banking, tax, pricing, and territory availability are active. The Release archive contains no local .storekit configuration or test bundle. TestFlight works, but App Review receives no product In TestFlight, using the real App Store sandbox and App Store Connect product configuration, Product.products(for:) returns the correct product, localized price, and title. The purchase sheet can be presented. During App Review, the same request rep
Replies
1
Boosts
0
Views
592
Activity
Aug ’26
Is it possible to intercept hardware (Bluetooth) keyboard events in an iOS Custom Keyboard Extension?
I'm developing an iOS custom keyboard extension and need to intercept external Bluetooth hardware keystrokes in the background. Can I capture these events within a UIInputViewController (e.g., using UIKeyCommand), or does iOS strictly route them directly to the host app? Are there any specific APIs or workarounds for this, or is it completely blocked by Apple's sandboxing policies?
Replies
1
Boosts
0
Views
657
Activity
Aug ’26
Reply to SFAuthorizationPluginView UI changes in macOS Golden Gate Beta – Unable to access the child elements and button controls using NSAccessibilityProtocol
Thanks for filing FB24412830. [quote='902166022, PrathibhaD, /thread/842397?answerId=902166022#902166022, /profile/PrathibhaD'] As this worked upto Tahoe … [/quote] Right, but that’s only because it was relying on implementation details. We don’t support folks navigating the view hierarchy in order to manipulate system views. So, when you ask about “intentional change” you need to consider what actually changed. The supported API hasn’t changed here. Rather, we’ve changed a bunch of implementation details. Was that intentional? Clearly. Was the intention to break your product? Probably not (although it’s not like I’d admit that if it were :-). My best guess is that these views have moved to a different process. Way back in the day macOS gained support for remote views, that is, a view that looks like it’s in an app’s window but is actually hosted in a completely different process. The canonical example of this is Powerbox, where we host the standard file open and save views in a separate process so that they
Topic: Privacy & Security SubTopic: General Tags:
Replies
Boosts
Views
Activity
Aug ’26
Reply to Sandbox denies mach-lookup com.apple.cloudd only when app is launched outside Xcode (CKError 6)
That fixed it. Thank you — and thank you for pushing me back to the recommended answer in the referenced thread. I had read the thread but missed that workaround entirely. For anyone finding this later, here is what my case looked like: My app uses CloudKit only indirectly, through NSPersistentCloudKitContainer. It never references a single CloudKit symbol of its own. So the framework was not loaded at launch, the sandbox came up without the iCloud exception, and the kernel denied com.apple.cloudd and com.apple.duetactivityscheduler — resulting in CKError 6 on every launch that did not come from Xcode. Launched by Xcode it always worked, which is what kept me looking in the wrong place. Adding a line that touches CloudKit at the very start of the launch path was enough. Everything else I had compared between a working app of mine and this one — entitlements and their values, embedded profiles and the entitlements they grant, provisioned devices, signing identity, Designated Requirement, quarantine, b
Topic: App & System Services SubTopic: iCloud Tags:
Replies
Boosts
Views
Activity
Aug ’26
How can a local AI agent use MLX/Metal unattended on macOS while remaining confined to an authorized workspace?
How can a local AI agent use MLX/Metal unattended while remaining confined to an authorized workspace? I am developing an AI-driven local media-processing workflow on an Apple-silicon Mac and am trying to understand the correct architecture for allowing it to run unattended without giving the AI agent unrestricted access to my primary personal computer. I am not a software engineer, so I may be missing an established macOS mechanism or using the wrong terminology. I would appreciate guidance from people familiar with MLX, Metal, sandboxing, and macOS security. What I am building I use OpenAI Codex as the local execution/software-development agent. The working system currently: ingests and verifies original video and still media while preserving immutable originals; performs visual semantic analysis and divides video into meaningful time-coded segments; separately analyzes spoken language rather than assuming audio and video are semantically equivalent; uses MLX Whisper locally on Apple silicon for ti
Replies
0
Boosts
0
Views
694
Activity
Aug ’26
Reply to Sandbox denies mach-lookup com.apple.cloudd only when app is launched outside Xcode (CKError 6)
Thanks for the pointer. That thread shows the same two sandbox denials, but the case there is a Store profile. Mine is a development profile, so I ran a controlled comparison of two of my own apps on one machine. The result is a contradiction I cannot explain, and I would appreciate guidance. Setup macOS 26.6.1, Xcode 26.6. Sandboxed macOS app, Core Data with NSPersistentCloudKitContainer, automatic signing, Apple Development certificate, Xcode-managed Mac Team Provisioning Profile. Symptom CloudKit fails with CKErrorDomain Code=6 whenever the app is launched by anything other than Xcode. The kernel logs: Sandbox: NoteManagerPro(44046) deny(1) mach-lookup com.apple.duetactivityscheduler Sandbox: NoteManagerPro(44046) deny(1) mach-lookup com.apple.cloudd Launched by Xcode, the same bundle works perfectly: the profile is evaluated, TCC approves the container, and there is real traffic to gateway.icloud.com with no errors. The control case A second app of mine on the same Mac,
Topic: App & System Services SubTopic: iCloud Tags:
Replies
Boosts
Views
Activity
Aug ’26
Reply to Transaction.finish() is a no-op on iOS 27 beta 5; purchase() then replays the same transaction forever
Also reproduces on StoreKit 1 — with daemon logs and server-side confirmation Same behaviour here through a different API. We use StoreKit 1 (SKPaymentQueue.finishTransaction:), not StoreKit 2, so the defect looks like it sits below both API surfaces. Device iPhone 17 Pro, iOS 27.0 from Aug 14, sandbox account, consumables. Transactions survive their own finish, are redelivered on every launch, and repeat buys replay the same transaction id with no sheet and no charge. We had a device log running, so here is where it fails — 8 finish attempts in the capture, 8 identical failures, 0 successes: storekitd [7ae43896_SK1] Starting request FinishTransactionRequest (accountRequirement: required(signIn: false, …), client: eu.nordeus.TopEleven Sandbox, destination: AMSBagKey(p2-in-app-transaction-done), …) storekitd [7ae43896_SK1] Account is required for request. error [7ae43896_SK1] Failed to encode request parameters (Never): Error Domain=NSCocoaErrorDomain Code=3840 JSON text did not start with ar
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Aug ’26