Search results for

“sandbox”

10,540 results found

Post

Replies

Boosts

Views

Activity

TestFlight: StoreKit 2 returns no consumables despite active agreements; HTTP 200 and empty product response
Hello, We are troubleshooting product discovery for three consumable In-App Purchases in our first iOS game, ION RUSH. All three remain unavailable in TestFlight. Environment and result: Physical iPhone 13, iOS 27.0.1 (24A446). App version 1.0 (80), installed through TestFlight. Direct native StoreKit 2; no RevenueCat or other purchase SDK. Product.products(for:) returns zero products before application filtering, without throwing an error. Earlier independent development-build diagnostics also returned zero products for batch and individual StoreKit 2 requests; SKProductsRequest reported all three identifiers as invalid. Checks completed: Product IDs exactly match App Store Connect: nova_pack_5, nova_pack_15, nova_pack_40. The explicit bundle identifier matches the app record and code; In-App Purchase is enabled for the App ID. All three consumables show Ready for Review, have prices and localizations, and are available in all 175 configured territories, including the US. Developer membership, Paid Apps Agre
0
0
91
3d
Empty Storekit Catalog Response
Hello all, I'm posting here today in hopes the internet can help me find a solution for an issue I'm having with integrating with subscriptions created in App Store Connect. I'm receiving no products back from StoreKit 2 for my list of product IDs. Things I've verified so far: No errors are coming from StoreKit The product IDs I'm requesting match the configured product IDs in the subscriptions The provisioning profile matches the bundle ID of the built app. The provisioning profile includes the in-app purchases capability. All subscriptions are priced, include localization, have an availability region set, and include a tax category. The subscriptions have been set for a week. Well over the typical one hour metadata update window. My banking, tax info, and paid apps agreement are up to date and active. I'm signed out of Media & Purchases and signed into a sandbox account under developer mode on the test device. The region of the sandbox account matches the region availability of the sub
0
0
281
4d
Reply to StoreKit 2 returns USD product metadata in TestFlight while the storefront is FRA/EUR
We are seeing a closely matching issue with UK pricing on iOS 27.0.1. In TestFlight, native StoreKit 2 Product.products(for:) returns USD metadata ($9.99 monthly / $79.99 annually), while Storefront.current reports GBR / 143444 immediately before and after the request. Apple's sandbox confirmation sheets show £9.99 monthly / £79.99 annually. We display Product.displayPrice unchanged and checked priceFormatStyle.currencyCode; there is no currency conversion. Grouped and individual product requests give the same USD result. A development-signed installation exported from the same archive returned GBP with a UK Sandbox account. Returning to TestFlight brought back USD. Signing out of Media & Purchases and checking the UK Sandbox account did not resolve it; those account steps were manually checked, not independently verified by the diagnostic. We have filed private feedback. Could Apple advise on a supported workaround or one targeted diagnostic to distinguish a TestFlight/account-
Topic: App & System Services SubTopic: StoreKit Tags:
4d
VZMacOSInstaller gave no completion callback before interruption; installation service logged socket sandbox denial and CSSM EPERM
Environment: Apple silicon host, macOS 15.6 (24G84). An arm64 command-line launcher is ad hoc signed; strict signature verification passes and its only entitlement is com.apple.security.virtualization. An Apple macOS 15.6 restore image reported a supported hardware model. The VM configuration validated with 4 vCPUs, 8 GiB RAM, a fresh macOS auxiliary store, a 64 GiB writable raw disk, and a separate read-only raw disk. No guest networking, directory sharing, or socket device was configured. One observed sequence: Load the restore image, select its supported hardware model, create the auxiliary store and disk, validate the VM configuration, then call VZMacOSInstaller.install(completionHandler:). The Apple installation service starts; its logs reach RestoreOS and show a signing-server response. The host logs also record the service's sandbox denial and repeated CSSM permission errors: Sandbox: com.apple.Virtualization.Install deny(1) network-outbound /private/var/run/systemkeychaincheck.socket
3
0
185
4d
401 error registering sandbox domain with Web Merchant Registration API
Hi, We recently applied for the Web Merchant Registration API and created our platform integrator ID. I am trying to register a domain in sandbox with the API: POST https://apple-pay-gateway-cert.apple.com/paymentservices/registerMerchant Content-Type: application/json { domainNames: [], partnerInternalMerchantIdentifier: , partnerMerchantName: , encryptTo: } Client certificate is provided via curl --cert/--key; the TLS 1.3 handshake completes successfully — the server requests the client cert, our Certificate + CERT verify are accepted, and the connection is established. But the response is { statusMessage: Payment Services Exception Unauthorized, statusCode: 401 } How do I go about debugging this?
0
0
297
5d
iPhone sync on MacOS Golden Gate 27.0.1 (26A434) caused data exposure out of sandbox
Hi guys, I connected iPhone using USB cable to Mac running Golden Gate 27.0.1 (26A434) and in Finder I selected iPhone to open sync page I was looking at Files tab and trying to get data from one of the apps. As I was doing that at certain point after disconnecting and connecting USB cable I wanted to avoid sync, so when dialog Trust this computer showed up on iPhone, I tapped Cancel. Then when disconnecting cable and connecting again, it started sync and under Files under the app in treeview original data disappeared (a database file and 2 folders with images) and iTunes_Control and Recordings folders showed up instead. I copied these folders to my Mac and there were files containing data. It looks like instead of Documents folder belonging to the app the sync mapped completely different storage location, which should have been protected by sandbox (I'm assuming). I clicked Eject icon in Finder, disconnected cable, connected again and it started sync, but ultimately failed with an error that some fi
1
0
180
5d
Reply to pushtotalk pushes accepted by APNs (200) are not delivered for several minutes after a delivered push
So, the delayed push issue you're describing is a longstanding behavior of APNS and is basically always caused by your device not being connected to the APNS server at the time the push was sent to the device. At a technical level, what's actually happening is that the push server queues your push for delivery and that push is then delivered at some later point when the device reconnects. FYI, the new CallKit delegate described here was SPECIFICALLY created to address this issue. There's no PTT equivalent to that API because PTT apps are able to discard/ignore pushes in a way CallKit apps cannot. Is there a limit, documented or expected, on how often the system delivers pushtotalk pushes or wakes the app after a recent incoming push? This isn't an app or system level issue. Could apns-expiration 0 cause these pushes to be discarded, for example if the device is briefly unreachable after a Push to Talk wake? Is a short non-zero expiration appropriate for pushtotalk? We've long recommended expiration 0 because
6d
Reply to Which IOUserClient entitlements are really required?
So, first off, if you'd like to see the DEXT entitlement check, the code is here in IOUserServer::serviceNewUserClient. I think I've generally described the check correctly, but it's also not the most straightforward code we've ever written. By default, DEXTs are only allowed to connect to processes signed by the same team as the DEXT. No entitlement is required for this. This could have been stated better, as it's really only relevant on iPadOS. Making the rules for iPadOS more explicit: The connecting app always needs com.apple.developer.driverkit.communicates-with-drivers. The DEXT then needs: If the DEXT only allows connections from its own team, no additional entitlement. If the DEXT wants to accept connections from other teams, it needs com.apple.developer.driverkit.allow-third-party-userclients”. I have not found this to be the case, at least not for communication between my CMIO Extension and my dext. As I talked about above, there are two sides to this equation. This entitlement here: For development
Topic: App & System Services SubTopic: Core OS Tags:
6d
StoreKit returns empty products for all IAPs after membership renewal (Paid Apps Agreement active, products approved)
Feedback: FB25016556 (includes sysdiagnose and device log archives) Since our Apple Developer Program membership lapsed on Sep 26, 2026 (renewed Sep 27), Product.products(for:) returns an empty array for every In-App Purchase of our app, in both production and sandbox. No error is thrown. Customers can't subscribe. App: bundle ID com.thefuntasty.gastromapa, live version 2.2.1 (worked fine until Sep 26, no code changes since). Products (both Approved, available in all countries, priced, localized): com.thefuntasty.gastromapa.subscription.premium (auto-renewable) com.thefuntasty.gastromapa.donation (non-consumable) Verified against TN3186 / TN3188: Membership active, latest Program License Agreement accepted (Account Holder checked) Paid Apps Agreement Active (effective Sep 29, 2026), nothing left to sign Bank account and tax forms Active Product IDs and bundle ID match the app record, In-App Purchase capability enabled on the explicit App ID Sandbox test build signed with a freshly regenerate
1
0
156
6d
pushtotalk pushes accepted by APNs (200) are not delivered for several minutes after a delivered push
Environment: iPhone 17 Pro, iOS 27.0, Xcode 27, dev build (aps-environment development), sandbox APNs, token-based auth. The app uses the PushToTalk framework with one restored channel; audio is WebRTC, started only after didActivate. Push headers: apns-push-type pushtotalk, apns-topic .voip-ptt, apns-priority 10, apns-expiration 0. Payload about 460 bytes. APNs returns 200 to every push in about 250 ms. What we then see is after a pushtotalk push is delivered and handled, the next push sent about 6 to 7 minutes later is not delivered to the app (no incomingPushResult call), although APNs returned 200. Pushes sent about 13 or more minutes after the last delivered one are almost always delivered. Overnight automated runs, phone on power, Focus off, no calls. Pushes sent after a delivered push: 38 of 38 lost (one run), 31 of 32 lost (another run). Pushes sent about 13+ minutes after the last delivered push: 38 of 40 delivered, and 37 of 41 in the other run. Lost pushes are not late: none arrived within
1
0
52
1w
Reply to Which IOUserClient entitlements are really required?
Kevin Elliot said By default, DEXTs are only allowed to connect to processes signed by the same team as the DEXT. No entitlement is required for this I have not found this to be the case, at least not for communication between my CMIO Extension and my dext. The Extension must be sandboxed, and UserClient Access is required to escape the sandbox. UserClient Access is managed, so it isn't available to me yet for my dext's bundle ID. For development, I use allow-any-userclient-access in the dext, but still have to use com.apple.security.temporary-exception.iokit-user-client-class in the extension to escape its mandatory sandbox.
Topic: App & System Services SubTopic: Core OS Tags:
1w
Reply to Sandboxed helper keeps running after the app is turned off in Background App Activity
Thanks, Quinn. We tried your static-plist suggestion on macOS 27.0 (26A428) in our Developer ID signed and notarized app: A root-owned plist at /Library/LaunchAgents/.plist has LimitLoadToSessionType=Background and AssociatedBundleIdentifiers=. It launches the nested App Sandbox helper. Our SMAppService system daemon calls launchctl kickstart user//. It bootstraps that fixed plist only if the job is not loaded in the service account's domain. After a cold boot and FileVault unlock, the helper published readiness as the hidden service account while /dev/console still belonged to root, before GUI login. Turning the app off in Background App Activity stopped the daemon. Its control socket closed, so the helper exited; the agent job stayed loaded. Turning the app back on started a new daemon and helper. These are observations on one OS release. Is this static plist plus kickstart arrangement within the intended launchd and Background Task Management model for a hidden-account Background agent, including
1w
Supported way to test Family Controls .child authorization without using a child's personal account?
I'm developing an iOS parent-child app that uses FamilyControls and DeviceActivity. Before distribution, I need to test AuthorizationCenter.shared.requestAuthorization(for: .child), including the guardian approval flow. So far I have tested .individual, which authenticates the device owner and does not exercise the child flow. Apple Developer Program Support directed me to this forum. What is the Apple-supported way to test this flow in this situation? Is there an Apple-supported test-only account or setup for this flow without using a child's personal Apple Account? If so, where are its requirements documented? If not, what is the recommended alternative? Can Sandbox Apple Accounts used for StoreKit Family Sharing tests be used to sign in to iCloud and test FamilyControls .child, or are they limited to purchase testing? Is there a supported simulator or other test method for guardian approval, or must this be verified using a child Apple Account in a real Family Sharing group on physical devices? I
0
0
81
1w
Reply to Sandboxed helper keeps running after the app is turned off in Background App Activity
[quote='907323022, mronian, /thread/848726?answerId=907323022#907323022, /profile/mronian'] Is there a supported way to get both? [/quote] I don’t think so. The only way to change users with launchd is to create a daemon with the UserName property, and that’s not gonna play well with App Sandbox. [quote='907323022, mronian, /thread/848726?answerId=907323022#907323022, /profile/mronian'] Which would you consider on firmer ground? [/quote] Definitely the first one. While it’s somewhat unusual, there’s an existing use case that relies on this, namely, a Network Extension that’s packaged as a system extension. And yep, that configuration uncovered some weird edge cases, but we treated those as bugs to be fixed (for example, this). However, I wouldn’t necessarily rule out your current approach. As I said, it’s not actually doing anything wrong, it’s just weird. If I were in your shoes I’d try this: Lay down a launchd.plist file in /Library/LaunchAgents. With LimitLoadToSessionType set to Background [1]. A
1w
Reply to Run codesign tool on Docker
@idontcare_ I have the right solution for you! I built a native container system for Mac called MacDocker, where you can run Mach-O binaries straight on macOS. No Linux VM, no emulation and Sandbox/seatbelt isolated. Have you tried to use your M4's GPU with a Docker container? Or build and sign your Swift code in Xcode it? Short answer: you can't. Docker Desktop and Apple Container runs a Linux VM, and it sees no Metal, no MPS, no MLX and no XCode. What Docker Desktop can't do, MacDocker can! 🔥 Real GPU access: PyTorch (MPS) and MLX using Apple Silicon's GPU and unified memory. 🛠️ Xcode in a container: upload your project .zip, get back a .dmg or .ipa signed with your certificate. ⚡ Containers up in ~130 ms: every job starts from an APFS clone (copy-on-write) — disk is used only for what changes. 🔒 Isolated by default: per-job macOS sandbox, dedicated service user, network blocked while running, and caps on memory (GPU included), processes and time. We are looking for beta testers. https:
Topic: Code Signing SubTopic: General Tags:
1w
TestFlight: StoreKit 2 returns no consumables despite active agreements; HTTP 200 and empty product response
Hello, We are troubleshooting product discovery for three consumable In-App Purchases in our first iOS game, ION RUSH. All three remain unavailable in TestFlight. Environment and result: Physical iPhone 13, iOS 27.0.1 (24A446). App version 1.0 (80), installed through TestFlight. Direct native StoreKit 2; no RevenueCat or other purchase SDK. Product.products(for:) returns zero products before application filtering, without throwing an error. Earlier independent development-build diagnostics also returned zero products for batch and individual StoreKit 2 requests; SKProductsRequest reported all three identifiers as invalid. Checks completed: Product IDs exactly match App Store Connect: nova_pack_5, nova_pack_15, nova_pack_40. The explicit bundle identifier matches the app record and code; In-App Purchase is enabled for the App ID. All three consumables show Ready for Review, have prices and localizations, and are available in all 175 configured territories, including the US. Developer membership, Paid Apps Agre
Replies
0
Boosts
0
Views
91
Activity
3d
Empty Storekit Catalog Response
Hello all, I'm posting here today in hopes the internet can help me find a solution for an issue I'm having with integrating with subscriptions created in App Store Connect. I'm receiving no products back from StoreKit 2 for my list of product IDs. Things I've verified so far: No errors are coming from StoreKit The product IDs I'm requesting match the configured product IDs in the subscriptions The provisioning profile matches the bundle ID of the built app. The provisioning profile includes the in-app purchases capability. All subscriptions are priced, include localization, have an availability region set, and include a tax category. The subscriptions have been set for a week. Well over the typical one hour metadata update window. My banking, tax info, and paid apps agreement are up to date and active. I'm signed out of Media & Purchases and signed into a sandbox account under developer mode on the test device. The region of the sandbox account matches the region availability of the sub
Replies
0
Boosts
0
Views
281
Activity
4d
Reply to StoreKit 2 returns USD product metadata in TestFlight while the storefront is FRA/EUR
We are seeing a closely matching issue with UK pricing on iOS 27.0.1. In TestFlight, native StoreKit 2 Product.products(for:) returns USD metadata ($9.99 monthly / $79.99 annually), while Storefront.current reports GBR / 143444 immediately before and after the request. Apple's sandbox confirmation sheets show £9.99 monthly / £79.99 annually. We display Product.displayPrice unchanged and checked priceFormatStyle.currencyCode; there is no currency conversion. Grouped and individual product requests give the same USD result. A development-signed installation exported from the same archive returned GBP with a UK Sandbox account. Returning to TestFlight brought back USD. Signing out of Media & Purchases and checking the UK Sandbox account did not resolve it; those account steps were manually checked, not independently verified by the diagnostic. We have filed private feedback. Could Apple advise on a supported workaround or one targeted diagnostic to distinguish a TestFlight/account-
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
4d
VZMacOSInstaller gave no completion callback before interruption; installation service logged socket sandbox denial and CSSM EPERM
Environment: Apple silicon host, macOS 15.6 (24G84). An arm64 command-line launcher is ad hoc signed; strict signature verification passes and its only entitlement is com.apple.security.virtualization. An Apple macOS 15.6 restore image reported a supported hardware model. The VM configuration validated with 4 vCPUs, 8 GiB RAM, a fresh macOS auxiliary store, a 64 GiB writable raw disk, and a separate read-only raw disk. No guest networking, directory sharing, or socket device was configured. One observed sequence: Load the restore image, select its supported hardware model, create the auxiliary store and disk, validate the VM configuration, then call VZMacOSInstaller.install(completionHandler:). The Apple installation service starts; its logs reach RestoreOS and show a signing-server response. The host logs also record the service's sandbox denial and repeated CSSM permission errors: Sandbox: com.apple.Virtualization.Install deny(1) network-outbound /private/var/run/systemkeychaincheck.socket
Replies
3
Boosts
0
Views
185
Activity
4d
401 error registering sandbox domain with Web Merchant Registration API
Hi, We recently applied for the Web Merchant Registration API and created our platform integrator ID. I am trying to register a domain in sandbox with the API: POST https://apple-pay-gateway-cert.apple.com/paymentservices/registerMerchant Content-Type: application/json { domainNames: [], partnerInternalMerchantIdentifier: , partnerMerchantName: , encryptTo: } Client certificate is provided via curl --cert/--key; the TLS 1.3 handshake completes successfully — the server requests the client cert, our Certificate + CERT verify are accepted, and the connection is established. But the response is { statusMessage: Payment Services Exception Unauthorized, statusCode: 401 } How do I go about debugging this?
Replies
0
Boosts
0
Views
297
Activity
5d
iPhone sync on MacOS Golden Gate 27.0.1 (26A434) caused data exposure out of sandbox
Hi guys, I connected iPhone using USB cable to Mac running Golden Gate 27.0.1 (26A434) and in Finder I selected iPhone to open sync page I was looking at Files tab and trying to get data from one of the apps. As I was doing that at certain point after disconnecting and connecting USB cable I wanted to avoid sync, so when dialog Trust this computer showed up on iPhone, I tapped Cancel. Then when disconnecting cable and connecting again, it started sync and under Files under the app in treeview original data disappeared (a database file and 2 folders with images) and iTunes_Control and Recordings folders showed up instead. I copied these folders to my Mac and there were files containing data. It looks like instead of Documents folder belonging to the app the sync mapped completely different storage location, which should have been protected by sandbox (I'm assuming). I clicked Eject icon in Finder, disconnected cable, connected again and it started sync, but ultimately failed with an error that some fi
Replies
1
Boosts
0
Views
180
Activity
5d
Reply to pushtotalk pushes accepted by APNs (200) are not delivered for several minutes after a delivered push
So, the delayed push issue you're describing is a longstanding behavior of APNS and is basically always caused by your device not being connected to the APNS server at the time the push was sent to the device. At a technical level, what's actually happening is that the push server queues your push for delivery and that push is then delivered at some later point when the device reconnects. FYI, the new CallKit delegate described here was SPECIFICALLY created to address this issue. There's no PTT equivalent to that API because PTT apps are able to discard/ignore pushes in a way CallKit apps cannot. Is there a limit, documented or expected, on how often the system delivers pushtotalk pushes or wakes the app after a recent incoming push? This isn't an app or system level issue. Could apns-expiration 0 cause these pushes to be discarded, for example if the device is briefly unreachable after a Push to Talk wake? Is a short non-zero expiration appropriate for pushtotalk? We've long recommended expiration 0 because
Replies
Boosts
Views
Activity
6d
Reply to Which IOUserClient entitlements are really required?
So, first off, if you'd like to see the DEXT entitlement check, the code is here in IOUserServer::serviceNewUserClient. I think I've generally described the check correctly, but it's also not the most straightforward code we've ever written. By default, DEXTs are only allowed to connect to processes signed by the same team as the DEXT. No entitlement is required for this. This could have been stated better, as it's really only relevant on iPadOS. Making the rules for iPadOS more explicit: The connecting app always needs com.apple.developer.driverkit.communicates-with-drivers. The DEXT then needs: If the DEXT only allows connections from its own team, no additional entitlement. If the DEXT wants to accept connections from other teams, it needs com.apple.developer.driverkit.allow-third-party-userclients”. I have not found this to be the case, at least not for communication between my CMIO Extension and my dext. As I talked about above, there are two sides to this equation. This entitlement here: For development
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
6d
StoreKit returns empty products for all IAPs after membership renewal (Paid Apps Agreement active, products approved)
Feedback: FB25016556 (includes sysdiagnose and device log archives) Since our Apple Developer Program membership lapsed on Sep 26, 2026 (renewed Sep 27), Product.products(for:) returns an empty array for every In-App Purchase of our app, in both production and sandbox. No error is thrown. Customers can't subscribe. App: bundle ID com.thefuntasty.gastromapa, live version 2.2.1 (worked fine until Sep 26, no code changes since). Products (both Approved, available in all countries, priced, localized): com.thefuntasty.gastromapa.subscription.premium (auto-renewable) com.thefuntasty.gastromapa.donation (non-consumable) Verified against TN3186 / TN3188: Membership active, latest Program License Agreement accepted (Account Holder checked) Paid Apps Agreement Active (effective Sep 29, 2026), nothing left to sign Bank account and tax forms Active Product IDs and bundle ID match the app record, In-App Purchase capability enabled on the explicit App ID Sandbox test build signed with a freshly regenerate
Replies
1
Boosts
0
Views
156
Activity
6d
pushtotalk pushes accepted by APNs (200) are not delivered for several minutes after a delivered push
Environment: iPhone 17 Pro, iOS 27.0, Xcode 27, dev build (aps-environment development), sandbox APNs, token-based auth. The app uses the PushToTalk framework with one restored channel; audio is WebRTC, started only after didActivate. Push headers: apns-push-type pushtotalk, apns-topic .voip-ptt, apns-priority 10, apns-expiration 0. Payload about 460 bytes. APNs returns 200 to every push in about 250 ms. What we then see is after a pushtotalk push is delivered and handled, the next push sent about 6 to 7 minutes later is not delivered to the app (no incomingPushResult call), although APNs returned 200. Pushes sent about 13 or more minutes after the last delivered one are almost always delivered. Overnight automated runs, phone on power, Focus off, no calls. Pushes sent after a delivered push: 38 of 38 lost (one run), 31 of 32 lost (another run). Pushes sent about 13+ minutes after the last delivered push: 38 of 40 delivered, and 37 of 41 in the other run. Lost pushes are not late: none arrived within
Replies
1
Boosts
0
Views
52
Activity
1w
Reply to Which IOUserClient entitlements are really required?
Kevin Elliot said By default, DEXTs are only allowed to connect to processes signed by the same team as the DEXT. No entitlement is required for this I have not found this to be the case, at least not for communication between my CMIO Extension and my dext. The Extension must be sandboxed, and UserClient Access is required to escape the sandbox. UserClient Access is managed, so it isn't available to me yet for my dext's bundle ID. For development, I use allow-any-userclient-access in the dext, but still have to use com.apple.security.temporary-exception.iokit-user-client-class in the extension to escape its mandatory sandbox.
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
1w
Reply to Sandboxed helper keeps running after the app is turned off in Background App Activity
Thanks, Quinn. We tried your static-plist suggestion on macOS 27.0 (26A428) in our Developer ID signed and notarized app: A root-owned plist at /Library/LaunchAgents/.plist has LimitLoadToSessionType=Background and AssociatedBundleIdentifiers=. It launches the nested App Sandbox helper. Our SMAppService system daemon calls launchctl kickstart user//. It bootstraps that fixed plist only if the job is not loaded in the service account's domain. After a cold boot and FileVault unlock, the helper published readiness as the hidden service account while /dev/console still belonged to root, before GUI login. Turning the app off in Background App Activity stopped the daemon. Its control socket closed, so the helper exited; the agent job stayed loaded. Turning the app back on started a new daemon and helper. These are observations on one OS release. Is this static plist plus kickstart arrangement within the intended launchd and Background Task Management model for a hidden-account Background agent, including
Replies
Boosts
Views
Activity
1w
Supported way to test Family Controls .child authorization without using a child's personal account?
I'm developing an iOS parent-child app that uses FamilyControls and DeviceActivity. Before distribution, I need to test AuthorizationCenter.shared.requestAuthorization(for: .child), including the guardian approval flow. So far I have tested .individual, which authenticates the device owner and does not exercise the child flow. Apple Developer Program Support directed me to this forum. What is the Apple-supported way to test this flow in this situation? Is there an Apple-supported test-only account or setup for this flow without using a child's personal Apple Account? If so, where are its requirements documented? If not, what is the recommended alternative? Can Sandbox Apple Accounts used for StoreKit Family Sharing tests be used to sign in to iCloud and test FamilyControls .child, or are they limited to purchase testing? Is there a supported simulator or other test method for guardian approval, or must this be verified using a child Apple Account in a real Family Sharing group on physical devices? I
Replies
0
Boosts
0
Views
81
Activity
1w
Reply to Sandboxed helper keeps running after the app is turned off in Background App Activity
[quote='907323022, mronian, /thread/848726?answerId=907323022#907323022, /profile/mronian'] Is there a supported way to get both? [/quote] I don’t think so. The only way to change users with launchd is to create a daemon with the UserName property, and that’s not gonna play well with App Sandbox. [quote='907323022, mronian, /thread/848726?answerId=907323022#907323022, /profile/mronian'] Which would you consider on firmer ground? [/quote] Definitely the first one. While it’s somewhat unusual, there’s an existing use case that relies on this, namely, a Network Extension that’s packaged as a system extension. And yep, that configuration uncovered some weird edge cases, but we treated those as bugs to be fixed (for example, this). However, I wouldn’t necessarily rule out your current approach. As I said, it’s not actually doing anything wrong, it’s just weird. If I were in your shoes I’d try this: Lay down a launchd.plist file in /Library/LaunchAgents. With LimitLoadToSessionType set to Background [1]. A
Replies
Boosts
Views
Activity
1w
Reply to Run codesign tool on Docker
@idontcare_ I have the right solution for you! I built a native container system for Mac called MacDocker, where you can run Mach-O binaries straight on macOS. No Linux VM, no emulation and Sandbox/seatbelt isolated. Have you tried to use your M4's GPU with a Docker container? Or build and sign your Swift code in Xcode it? Short answer: you can't. Docker Desktop and Apple Container runs a Linux VM, and it sees no Metal, no MPS, no MLX and no XCode. What Docker Desktop can't do, MacDocker can! 🔥 Real GPU access: PyTorch (MPS) and MLX using Apple Silicon's GPU and unified memory. 🛠️ Xcode in a container: upload your project .zip, get back a .dmg or .ipa signed with your certificate. ⚡ Containers up in ~130 ms: every job starts from an APFS clone (copy-on-write) — disk is used only for what changes. 🔒 Isolated by default: per-job macOS sandbox, dedicated service user, network blocked while running, and caps on memory (GPU included), processes and time. We are looking for beta testers. https:
Topic: Code Signing SubTopic: General Tags:
Replies
Boosts
Views
Activity
1w