Search results for

“sandbox”

10,542 results found

Post

Replies

Boosts

Views

Activity

Reply to AppStore.ageRatingCode always returns 0 on real device — is this expected behavior?
Hi Joycity, thank you for your question! The ageRatingCode API should be used to observe changes to your app's age rating over time by comparing to its last known value. If your app's age rating code has changed, consider informing parents or guardians by using the Significant Change API. A value of 0 is expected during development of your app when it is built and run from Xcode and Sandbox environments (including TestFlight).
Topic: App & System Services SubTopic: StoreKit Tags:
Jul ’26
App Transfer blocked by "sharing a group container" error for iOS VPN app
Hello everyone, We are trying to transfer a published iOS VPN app between Apple Developer accounts. The transfer is blocked by an error that we cannot understand. Hoping someone here has faced this and can share insight. About the app The app is a VPN client for iOS It uses an App Group to enable communication between the main app and its Network Extension The App Group is not shared with any other application in the account — it is used only within this single app The error When attempting Transfer App in App Store Connect, we get exactly this error: You can only transfer sandboxed apps that are not sharing a group container. Our question How can we transfer this app, and what might be causing this error in our case? Any insight would be greatly appreciated. Thank you.
0
0
194
Jul ’26
Reply to Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
I've already added a reveal probe alongside the existing raw-read and open -g probes, using open -g -R , which goes through the same Finder-reveal service you described rather than opening the file's content. Unfortunately, I'm not sure this will work or not. While open -g -R does eventually call activateFileViewerSelectingURLs, what it actually does is: Perform its own existence checks (which could conceivably fail). Calls NSWorkspace.selectFile(_:inFileViewerRootedAtPath:), which does its own existence checks. ...and then calls activateFileViewerSelectingURLs. Depending on the process state, it's possible that 1 or 2 might fail, even though the Finder might actually still be able to access the file. What's different about activateFileViewerSelectingURLs itself is that it doesn't actually implement ANY checks, but just sends the input directly to the Finder. There's no Finder interaction anywhere in that path; a human isn't browsing these files. One minor clarification here. The Finder itself isn't necessar
Topic: App & System Services SubTopic: Core OS Tags:
Jul ’26
Reply to Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
Kevin, Thanks for the clarification on open vs. NSWorkspace.activateFileViewerSelectingURLs / Show in Finder — that's a useful distinction I hadn't considered (preflighting + the event-emission restrictions). I've already added a reveal probe alongside the existing raw-read and open -g probes, using open -g -R , which goes through the same Finder-reveal service you described rather than opening the file's content. It's wired into the same sentinel locations and fires on the next confirmed deny(1) cluster. One cluster hit today right after I deployed it, but the timing meant the new probe only got a clean result on the control location outside any mount (not denied, as expected) — no denial data on the mount points themselves yet. I'll follow up with real numbers once a few more clusters accumulate, same as the raw/open() data I posted last time. To answer your question directly — what do we actually need to work: the process driving most of this is a background daemon (launchd, no interactive session, no Term
Topic: App & System Services SubTopic: Core OS Tags:
Jul ’26
macOS: Remote push notification accepted by APNs (HTTP 200) but never displayed — application(_:didReceiveRemoteNotification:) fires instead of willPresent
I'm running a PoC to validate remote push notification delivery on macOS (AppKit, no Storyboard, programmatic setup) using UNUserNotificationCenter. Environment: macOS Version 26.5 (25F71) Xcode Version 26.2 (17C52) App: sandboxed, entitlements include aps-environment: development, Push Notifications + Background Modes (Remote notifications) capabilities enabled Auth: token-based (.p8 key, ES256 JWT), sent via curl directly to api.sandbox.push.apple.com Setup: UNUserNotificationCenter.current().requestAuthorization(options: [.alert, .badge, .sound]) { granted, error in if granted { NSApplication.shared.registerForRemoteNotifications() } } Delegate implements both: func userNotificationCenter(_ center: UNUserNotificationCenter, willPresent notification: UNNotification, withCompletionHandler completionHandler: @escaping (UNNotificationPresentationOptions) -> Void) and the legacy: func application(_ application: NSApplication, didReceiveRemoteNotification userInfo: [String: Any]) Repro steps: App lau
1
0
1.4k
Jul ’26
Reply to Is Sandboxing possible for Command line app run with sudo
Like Albert, I’m curious as to what you’re actual goal is here. Can you take a step back and explain more about the big picture here? Some random thoughts: You can’t distribute a command-line tool in the App Store, so you have the option of disabling App Sandbox. Is there a specific reason you need to enable it? It is possible to sandbox a command-line tool, but it’s quite unusual. It is possible for combine App Sandbox and running as root [1] but, again, it’s quite unusual. When you run a tool using sudo it ends up in a mixed execution environment. Trying to combine that with App Sandbox puts you fare off the beaten path. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com [1] One place you see this is when you package a Network Extension as a sysex.
Topic: App & System Services SubTopic: Core OS Tags:
Jul ’26
Is there any API or Entitlement to detect the active foreground app in real-time?
Hi everyone, I am currently working on a specialized analytics and time-tracking application, and I am trying to find a reliable way to detect which app the user currently has open in the foreground in real-time. On Android, this is typically handled via Accessibility Services or UsageStats, but I am well aware of iOS’s strict sandboxing rules and privacy protections. So far, I have researched and tested a few workarounds, but none perfectly fit the use case: Screen Time API (FamilyControls / DeviceActivity): This is fantastic for blocking apps or getting daily aggregate usage, but it does not provide real-time callbacks or the bundle ID of the app currently on the screen. MDM (Mobile Device Management): Requires enterprise enrollment and wiping the device, which isn't feasible for a consumer-facing app. ReplayKit (Broadcast Extension): We are currently utilizing RPBroadcastSampleHandler to screen record the device and using OCR and Core ML to visually identify the app (e.g., detecting the YouTube UI
1
0
958
Jul ’26
App Reviewers Keep Responding With Nonsense Rejections
I built what Apple would describe as a reader app. Because it involves legal and financial information, however, it doesn't qualify as a standard news reader, so Apple is not treating as a reader app. That means it needs to have in-app subscriptions. Fine. I think that's a better UI choice for the user anyway. The problem is that the App Store Connect UI for subscriptions and the training materials for Apple's reviewers on subscriptions are horrendous. As my other posts on these forums have documented, they literally do not work. Now with the app in the review process, the reviewers keep sending back rejections because they keep trying to sign up for a subscription with the provided demo account that is already signed up. Why is the demo account already signed up? Because it's a demo account! And that's what Apple wants (to test each and every feature)! Fortunately, there are additional in-app subscription sandbox accounts I've provided credentials for so that from a clean slate, the reviewers can ch
1
0
221
Jul ’26
Reply to Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
One more wrinkle worth flagging: for test_pi_root, the two probe methods disagreed at least once — at 2026-07-11 10:23, the raw open() call was denied but the open -g (LaunchServices) call succeeded. Unfortunately, after taking a closer look, open doesn't quite do the test I wanted. It basically works the way I described but it also preflight the paths it's given. There are also some tricky issues around exactly what event a process is allowed to emit, both of which mean open can end up failing even if the user/app target would be allowed to access the file. The better test here would be to see if the Finder by calling NSWorkspace.activateFileViewerSelectingURLs. That method actually works through the Show in Finder service (which you could also use instead), which means it avoids all sandbox/security issues. The Finder is directly given the path as a string, so all that matters is its own access restrictions. The control mount I set up specifically to test your workaround suggestion (relocate outsid
Topic: App & System Services SubTopic: Core OS Tags:
Jul ’26
Reply to Is Sandboxing possible for Command line app run with sudo
@TataChaitanya Thank you for your post. Is your question related to submitting a terminal application to the App Store? I believe but I have been wrong before, the App Sandbox is enforced at the kernel level. Even if you execute your application as root using sudo, the kernel will still enforce the sandbox restrictions. If your application requires sudo to access system files (such as /etc), read other users’ data, or bind to low ports, the sandbox should block these actions regardless of whether the application is running as root. If this is a standalone command-line tool intended to be run by administrators via sudo, simply do not enable the App Sandbox capability. Command-line tools are not required to be sandboxed unless they are being bundled within a sandboxed Mac App Store application. Additionally, please review the types of applications accepted at the store. Is this a Mac App? If your Swift application genuinely requires root privileges to functi
Topic: App & System Services SubTopic: Core OS Tags:
Jul ’26
IAP Products Not Loading During App Review - Sandbox Environment Issue (Guideline 2.1b)
Hello, We are experiencing an issue where our In-App Purchase products fail to load during App Review, but work correctly in TestFlight using the exact same build. App Details: Framework: React Native (Expo) with RevenueCat SDK Products: 4 auto-renewable subscriptions Important context: Our app has been through multiple review cycles. In earlier submissions (builds 3 and 4), the IAP products loaded correctly and the reviewer was able to see the prices on the same review device (iPad Air 11-inch M3). However, in our most recent submissions, the exact same implementation is no longer loading products during review, despite working correctly in TestFlight. What works on our side: StoreKit successfully returns all subscription products RevenueCat offerings load correctly Localized pricing is displayed properly Purchases complete successfully Restore purchases work as expected Tested on multiple physical devices with sandbox accounts What happens during App Review: The paywall shows — instead of prices Pr
0
0
418
Jul ’26
Add Bank Account fails with "Something went wrong" right after selecting Country
I am completely blocked from adding a bank account to my account, which is holding up my Paid Applications Agreement. Summary When I try to add a bank account in App Store Connect, the flow fails the moment I select a Country/Region and click Next. Instead of the bank details form, I get a full page error: Something went wrong. Please try again. There is a Refresh button, but refreshing just returns to the same error. The bank details form never appears, so I can never enter any bank information. Steps to reproduce Sign in to App Store Connect as the Account Holder. Go to Business, then Agreements. Under the Paid Applications Agreement, click Add Bank Account (also tried the Add Bank Account link under Bank Accounts). On the bank account screen, select the Country/Region for the account. Click Next. The page immediately shows Something went wrong. Please try again. No form loads. Current account state Role: Account Holder. Paid Applications Agreement: status Pending User Info. It is signed, and the only remai
0
0
116
Jul ’26
Reply to Sandboxed Mac app denied mach-lookup com.apple.cloudd when signed with Mac Team Store Provisioning Profile on macOS 26
[quote='897181022, Reishandy, /thread/835400?answerId=897181022#897181022, /profile/Reishandy'] full output in the next comment [/quote] App Store install Executable=/Applications/YouriBeaconSimulator.app/Contents/MacOS/YouriBeaconSimulator [Dict] [Key] com.apple.application-identifier [Value] [String] 6H8PJSZGXA.id.reishandy.YouriBeaconSimulator [Key] com.apple.developer.aps-environment [Value] [String] production [Key] com.apple.developer.icloud-container-environment [Value] [String] Production [Key] com.apple.developer.icloud-container-identifiers [Value] [Array] [String] iCloud.id.reishandy.YouriBeaconSimulator [Key] com.apple.developer.icloud-services [Value] [Array] [String] CloudKit [Key] com.apple.developer.team-identifier [Value] [String] 6H8PJSZGXA [Key] com.apple.security.app-sandbox [Value] [Bool] true [Key] com.apple.security.device.bluetooth [Value] [Bool] true [Key] com.apple.security.files.user-selected.read-only [Value] [Bool] true [Key] com.apple.security.network.client [Value] [Boo
Topic: App & System Services SubTopic: iCloud Tags:
Jul ’26
Reply to AppStore.ageRatingCode always returns 0 on real device — is this expected behavior?
Hi Joycity, thank you for your question! The ageRatingCode API should be used to observe changes to your app's age rating over time by comparing to its last known value. If your app's age rating code has changed, consider informing parents or guardians by using the Significant Change API. A value of 0 is expected during development of your app when it is built and run from Xcode and Sandbox environments (including TestFlight).
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Jul ’26
App Transfer blocked by "sharing a group container" error for iOS VPN app
Hello everyone, We are trying to transfer a published iOS VPN app between Apple Developer accounts. The transfer is blocked by an error that we cannot understand. Hoping someone here has faced this and can share insight. About the app The app is a VPN client for iOS It uses an App Group to enable communication between the main app and its Network Extension The App Group is not shared with any other application in the account — it is used only within this single app The error When attempting Transfer App in App Store Connect, we get exactly this error: You can only transfer sandboxed apps that are not sharing a group container. Our question How can we transfer this app, and what might be causing this error in our case? Any insight would be greatly appreciated. Thank you.
Replies
0
Boosts
0
Views
194
Activity
Jul ’26
Reply to Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
I've already added a reveal probe alongside the existing raw-read and open -g probes, using open -g -R , which goes through the same Finder-reveal service you described rather than opening the file's content. Unfortunately, I'm not sure this will work or not. While open -g -R does eventually call activateFileViewerSelectingURLs, what it actually does is: Perform its own existence checks (which could conceivably fail). Calls NSWorkspace.selectFile(_:inFileViewerRootedAtPath:), which does its own existence checks. ...and then calls activateFileViewerSelectingURLs. Depending on the process state, it's possible that 1 or 2 might fail, even though the Finder might actually still be able to access the file. What's different about activateFileViewerSelectingURLs itself is that it doesn't actually implement ANY checks, but just sends the input directly to the Finder. There's no Finder interaction anywhere in that path; a human isn't browsing these files. One minor clarification here. The Finder itself isn't necessar
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jul ’26
Reply to Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
Kevin, Thanks for the clarification on open vs. NSWorkspace.activateFileViewerSelectingURLs / Show in Finder — that's a useful distinction I hadn't considered (preflighting + the event-emission restrictions). I've already added a reveal probe alongside the existing raw-read and open -g probes, using open -g -R , which goes through the same Finder-reveal service you described rather than opening the file's content. It's wired into the same sentinel locations and fires on the next confirmed deny(1) cluster. One cluster hit today right after I deployed it, but the timing meant the new probe only got a clean result on the control location outside any mount (not denied, as expected) — no denial data on the mount points themselves yet. I'll follow up with real numbers once a few more clusters accumulate, same as the raw/open() data I posted last time. To answer your question directly — what do we actually need to work: the process driving most of this is a background daemon (launchd, no interactive session, no Term
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jul ’26
macOS: Remote push notification accepted by APNs (HTTP 200) but never displayed — application(_:didReceiveRemoteNotification:) fires instead of willPresent
I'm running a PoC to validate remote push notification delivery on macOS (AppKit, no Storyboard, programmatic setup) using UNUserNotificationCenter. Environment: macOS Version 26.5 (25F71) Xcode Version 26.2 (17C52) App: sandboxed, entitlements include aps-environment: development, Push Notifications + Background Modes (Remote notifications) capabilities enabled Auth: token-based (.p8 key, ES256 JWT), sent via curl directly to api.sandbox.push.apple.com Setup: UNUserNotificationCenter.current().requestAuthorization(options: [.alert, .badge, .sound]) { granted, error in if granted { NSApplication.shared.registerForRemoteNotifications() } } Delegate implements both: func userNotificationCenter(_ center: UNUserNotificationCenter, willPresent notification: UNNotification, withCompletionHandler completionHandler: @escaping (UNNotificationPresentationOptions) -> Void) and the legacy: func application(_ application: NSApplication, didReceiveRemoteNotification userInfo: [String: Any]) Repro steps: App lau
Replies
1
Boosts
0
Views
1.4k
Activity
Jul ’26
Reply to Is Sandboxing possible for Command line app run with sudo
Like Albert, I’m curious as to what you’re actual goal is here. Can you take a step back and explain more about the big picture here? Some random thoughts: You can’t distribute a command-line tool in the App Store, so you have the option of disabling App Sandbox. Is there a specific reason you need to enable it? It is possible to sandbox a command-line tool, but it’s quite unusual. It is possible for combine App Sandbox and running as root [1] but, again, it’s quite unusual. When you run a tool using sudo it ends up in a mixed execution environment. Trying to combine that with App Sandbox puts you fare off the beaten path. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com [1] One place you see this is when you package a Network Extension as a sysex.
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jul ’26
Is there any API or Entitlement to detect the active foreground app in real-time?
Hi everyone, I am currently working on a specialized analytics and time-tracking application, and I am trying to find a reliable way to detect which app the user currently has open in the foreground in real-time. On Android, this is typically handled via Accessibility Services or UsageStats, but I am well aware of iOS’s strict sandboxing rules and privacy protections. So far, I have researched and tested a few workarounds, but none perfectly fit the use case: Screen Time API (FamilyControls / DeviceActivity): This is fantastic for blocking apps or getting daily aggregate usage, but it does not provide real-time callbacks or the bundle ID of the app currently on the screen. MDM (Mobile Device Management): Requires enterprise enrollment and wiping the device, which isn't feasible for a consumer-facing app. ReplayKit (Broadcast Extension): We are currently utilizing RPBroadcastSampleHandler to screen record the device and using OCR and Core ML to visually identify the app (e.g., detecting the YouTube UI
Replies
1
Boosts
0
Views
958
Activity
Jul ’26
App Reviewers Keep Responding With Nonsense Rejections
I built what Apple would describe as a reader app. Because it involves legal and financial information, however, it doesn't qualify as a standard news reader, so Apple is not treating as a reader app. That means it needs to have in-app subscriptions. Fine. I think that's a better UI choice for the user anyway. The problem is that the App Store Connect UI for subscriptions and the training materials for Apple's reviewers on subscriptions are horrendous. As my other posts on these forums have documented, they literally do not work. Now with the app in the review process, the reviewers keep sending back rejections because they keep trying to sign up for a subscription with the provided demo account that is already signed up. Why is the demo account already signed up? Because it's a demo account! And that's what Apple wants (to test each and every feature)! Fortunately, there are additional in-app subscription sandbox accounts I've provided credentials for so that from a clean slate, the reviewers can ch
Replies
1
Boosts
0
Views
221
Activity
Jul ’26
Reply to Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
One more wrinkle worth flagging: for test_pi_root, the two probe methods disagreed at least once — at 2026-07-11 10:23, the raw open() call was denied but the open -g (LaunchServices) call succeeded. Unfortunately, after taking a closer look, open doesn't quite do the test I wanted. It basically works the way I described but it also preflight the paths it's given. There are also some tricky issues around exactly what event a process is allowed to emit, both of which mean open can end up failing even if the user/app target would be allowed to access the file. The better test here would be to see if the Finder by calling NSWorkspace.activateFileViewerSelectingURLs. That method actually works through the Show in Finder service (which you could also use instead), which means it avoids all sandbox/security issues. The Finder is directly given the path as a string, so all that matters is its own access restrictions. The control mount I set up specifically to test your workaround suggestion (relocate outsid
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jul ’26
Reply to Is Sandboxing possible for Command line app run with sudo
@TataChaitanya Thank you for your post. Is your question related to submitting a terminal application to the App Store? I believe but I have been wrong before, the App Sandbox is enforced at the kernel level. Even if you execute your application as root using sudo, the kernel will still enforce the sandbox restrictions. If your application requires sudo to access system files (such as /etc), read other users’ data, or bind to low ports, the sandbox should block these actions regardless of whether the application is running as root. If this is a standalone command-line tool intended to be run by administrators via sudo, simply do not enable the App Sandbox capability. Command-line tools are not required to be sandboxed unless they are being bundled within a sandboxed Mac App Store application. Additionally, please review the types of applications accepted at the store. Is this a Mac App? If your Swift application genuinely requires root privileges to functi
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jul ’26
Is Sandboxing possible for Command line app run with sudo
Hi Team, If I want to create a command line app in swift which needs to be invoked using sudo, will I be able to sandbox this app?
Replies
2
Boosts
0
Views
775
Activity
Jul ’26
IAP Products Not Loading During App Review - Sandbox Environment Issue (Guideline 2.1b)
Hello, We are experiencing an issue where our In-App Purchase products fail to load during App Review, but work correctly in TestFlight using the exact same build. App Details: Framework: React Native (Expo) with RevenueCat SDK Products: 4 auto-renewable subscriptions Important context: Our app has been through multiple review cycles. In earlier submissions (builds 3 and 4), the IAP products loaded correctly and the reviewer was able to see the prices on the same review device (iPad Air 11-inch M3). However, in our most recent submissions, the exact same implementation is no longer loading products during review, despite working correctly in TestFlight. What works on our side: StoreKit successfully returns all subscription products RevenueCat offerings load correctly Localized pricing is displayed properly Purchases complete successfully Restore purchases work as expected Tested on multiple physical devices with sandbox accounts What happens during App Review: The paywall shows — instead of prices Pr
Replies
0
Boosts
0
Views
418
Activity
Jul ’26
Add Bank Account fails with "Something went wrong" right after selecting Country
I am completely blocked from adding a bank account to my account, which is holding up my Paid Applications Agreement. Summary When I try to add a bank account in App Store Connect, the flow fails the moment I select a Country/Region and click Next. Instead of the bank details form, I get a full page error: Something went wrong. Please try again. There is a Refresh button, but refreshing just returns to the same error. The bank details form never appears, so I can never enter any bank information. Steps to reproduce Sign in to App Store Connect as the Account Holder. Go to Business, then Agreements. Under the Paid Applications Agreement, click Add Bank Account (also tried the Add Bank Account link under Bank Accounts). On the bank account screen, select the Country/Region for the account. Click Next. The page immediately shows Something went wrong. Please try again. No form loads. Current account state Role: Account Holder. Paid Applications Agreement: status Pending User Info. It is signed, and the only remai
Replies
0
Boosts
0
Views
116
Activity
Jul ’26
Reply to Sandboxed Mac app denied mach-lookup com.apple.cloudd when signed with Mac Team Store Provisioning Profile on macOS 26
[quote='897181022, Reishandy, /thread/835400?answerId=897181022#897181022, /profile/Reishandy'] full output in the next comment [/quote] App Store install Executable=/Applications/YouriBeaconSimulator.app/Contents/MacOS/YouriBeaconSimulator [Dict] [Key] com.apple.application-identifier [Value] [String] 6H8PJSZGXA.id.reishandy.YouriBeaconSimulator [Key] com.apple.developer.aps-environment [Value] [String] production [Key] com.apple.developer.icloud-container-environment [Value] [String] Production [Key] com.apple.developer.icloud-container-identifiers [Value] [Array] [String] iCloud.id.reishandy.YouriBeaconSimulator [Key] com.apple.developer.icloud-services [Value] [Array] [String] CloudKit [Key] com.apple.developer.team-identifier [Value] [String] 6H8PJSZGXA [Key] com.apple.security.app-sandbox [Value] [Bool] true [Key] com.apple.security.device.bluetooth [Value] [Bool] true [Key] com.apple.security.files.user-selected.read-only [Value] [Bool] true [Key] com.apple.security.network.client [Value] [Boo
Topic: App & System Services SubTopic: iCloud Tags:
Replies
Boosts
Views
Activity
Jul ’26
Tips for an efficient app review
To learn how to best prepare your app for an efficient review, visit Test your app on compatible devices, Configure In-App Purchases for review in the sandbox, and Provide information for a complete review on App Review Help.
Replies
0
Boosts
0
Views
2.5k
Activity
Jul ’26