Search results for

“sandbox”

10,542 results found

Post

Replies

Boosts

Views

Activity

Reply to Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
Thanks for looking into this. Re: timing — I can't give you a clean before/after-26.5 comparison. This specific NFS mount setup only went live on 2026-07-03, and I was already on 26.5.1/26.5.2 (25F84) at that point — so I have no data on this exact mount configuration under an earlier OS version. I did run a different mount method (SSHFS/macFUSE) at the same path before that, on earlier OS builds, but it failed differently (kext/Gatekeeper corruption), not with this deny(1) signature — so I can't say this is a regression tied to a specific OS version, only that it's new since I switched mount methods. Re: the StorageKit/r.171126338 log line — the timestamp you posted (2026-07-05 10:52:14+0200) lands within seconds of a deny(1) cluster I already captured a full sysdiagnose for (10:52:11–10:52:54, attached to FB23576006). I'll dig through that archive specifically for the StorageKit/SKManager entries around r.171126338 and report back what I find. Re: the workaround — good lead, and it lines up with something I
Topic: App & System Services SubTopic: Core OS Tags:
Jul ’26
Reply to Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
I'm seeing a recurring issue on macOS 26.5.2 (build 25F84) where the kernel's Sandbox/System Policy layer intermittently denies file access on NFS mount points from local network servers. Did this JUST start happening in 26.5? If not, do you know when it might have started? There was change at that time (r.171126338) which also introduced this error: 2026-07-05 10:52:14.292554+0200 diskutil: (StorageKit) [com.apple.storagekit:general] -[SKManager _diskForPath:isNetworkMount:]: open() failed: errno=1 I'm not sure how that would then connect to the failure you're seeing, but I think it might be connected to this. or has a workaround, So, the one thing I would try is moving the mount point out of /Users/Shared/ and into a location you more directly control- either a new directory in your home directory or a new directory you create within the system hierarchy. Creating your own directory helps shift you out of the systems normal view, which can reduce the possibility of unrelated activity disrupting you
Topic: App & System Services SubTopic: Core OS Tags:
Jul ’26
Reply to Supported way to use MapKit in a sandboxed macOS Quick Look extension?
@DTS Engineer I think your explanation is not entirely accurate. Actually the sandbox is already treating different system components differently. Therefore it seems very unlikely that the sandbox can not distinguish between allowed and forbidden network traffic. MapKit is an encapsulated system component, so it is more or less impossible for a Quicklook extension to send random and uncontrolled network requests. All the network access is completely controlled by the system. So it seems extremely unlikely that there are serious security issues here. BTW: in the past, MapKit did work in Quicklook extensions. On the other hand, WebKit (WKWebView) is(!) working in Quicklook extensions just fine. But unlike MapKit, WebKit is able to do random and uncontrolled network requests, therefore could be a security issue. Which means the sandbox is actually distinguishing between different system components. The harmless one it does block, the dangerous one it let pass. I do understand that WebK
Jul ’26
Reply to ShazamKit under the App Sandbox on macOS — sanctioned way to reach com.apple.shazamd? (error 202)
[quote='837008021, DANgerous25, /thread/837008, /profile/DANgerous25'] The iOS entitlement com.apple.developer.shazamkit is rejected by the macOS validator at upload [/quote] My undestanding is that this entitlement isn’t valid on iOS either. See here. [quote='837008021, DANgerous25, /thread/837008, /profile/DANgerous25'] Is it correct to place the exception on the main app … rather than on the helper itself? [/quote] That depends on how you run the helper. If you spawn it as a child process then it inherits your app’s static sandbox and thus adding entitlement to the parent app is the right choice. As to your main issue, am I right in assuming that this nested helper stuff isn’t a factor there? That is, the behaviour you’ve described applies regardless whether you run the code in your helper or in your main app? Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Topic: Media Technologies SubTopic: General Tags:
Jul ’26
How can a SwiftUI drag provide the actual file URL of an existing file on macOS (as NSOutlineView does)?
I'm dragging existing files from a SwiftUI List (a search result list in a sandboxed, document-based Mac app), and I want drop targets to receive the actual file URL — the same behavior as AppKit's NSOutlineView with outlineView(_:pasteboardWriterForItem:) returning an NSURL: the Finder copies the file, browsers load it, and text views insert its path. My current implementation is Transferable-based: FileRepresentation(exportedContentType: .data) { item in SentTransferredFile(item.fileURL, allowAccessingOriginalFile: true) } .suggestedFileName(.fileURL.lastPathComponent) With this, what receivers get is a temporary copy in the app's own container (Caches/com.apple.SwiftUI.Drag-/), not the actual file URL — despite allowAccessingOriginalFile: true. Dropping on the Finder or onto an application icon works through the copy, but receivers that interpret the URL itself — a browser window, or a text view that inserts the dropped file's path — see the temporary container path. Note that the dragged files li
3
0
661
Jul ’26
Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
I'm seeing a recurring issue on macOS 26.5.2 (build 25F84) where the kernel's Sandbox/System Policy layer intermittently denies file access on NFS mount points from local network servers. Posting here in case anyone recognizes this pattern or has a workaround, and flagging it since I've also filed a Feedback Assistant report (with a live-captured sysdiagnose) for the same issue. WHAT HAPPENS Two independent NFS mounts to two separate, unrelated servers on my LAN start failing simultaneously with Operation not permitted. The kernel log shows: kernel: (Sandbox) System Policy: mount_nfs(PID) deny(1) file-mount /path/to/mount Critically, it's not limited to the mount syscall - within the same few-second window, System Policy also denies ls, perl, diskutil, and even umount -f on the exact same path, for otherwise unrelated processes. So it looks like a transient, path-scoped kernel decision rather than something specific to NFS or the mount syscall. It self-heals anywhere from seconds to ~30 minu
21
0
1.9k
Jul ’26
ShazamKit under the App Sandbox on macOS — sanctioned way to reach com.apple.shazamd? (error 202)
I'm building a music-recognition app for the Mac App Store that uses ShazamKit (SHSession / SHManagedSession) against the default Shazam catalog. In a sandboxed build, SHSession.match(_:) fails with: com.apple.ShazamKit error 202 — The connection to service named com.apple.shazamd was invalidated The root cause is a sandbox denial of the mach-lookup to the ShazamKit matching daemon: kernel (Sandbox): deny(1) mach-lookup com.apple.shazamd What I've established: Enabling the ShazamKit App Service on the App ID does not add com.apple.shazamd to the sandbox mach-lookup allow-list on macOS — the denial persists and matching returns error 202. The iOS entitlement com.apple.developer.shazamkit is rejected by the macOS validator at upload (not supported on macOS), so it isn't an option here. Adding com.apple.security.temporary-exception.mach-lookup.global-name = [com.apple.shazamd] to the app's entitlements removes the denial, and ShazamKit then matches correctly under the sandbox
5
0
1.1k
Jul ’26
Cannot load products in Sandbox
Hi, I'm trying to hook up some test in app purchases to test purchase code between our app and our app's backend. When I try to load products (requestProductData) with my Sandbox account, my product identifiers come back in the invalid product identifiers member of the response. My product says it's in waiting for review status in app store connect, and I'm logged in to the app store with my sandbox account on my device. We just accepted the paid apps agreement as well--is there some propagation time to that? The product ID I'm using (both in app store connect and in-app) is test_durable. Do I need to append the package name to that or something? I've dug through the docs and through the forums here and come up empty. I tried using the Xcode storekit test harness and the issue there is that because that doesn't actually talk to the store apis, I can't use that to test my backend correctly validating/processing the transactions. Thanks!
0
0
466
Jul ’26
In App Purchase Sandbox Testing - Clear Purchase History Not Working
I'm testing iAP in a sandbox account (as configured in App Store Connect under 'Sandbox Testers'). So the in app purchase works. Cool. But I wanted to retry it. So I cleared the purchase history (both in App Store Connect and on my iPad in the 'Developer' section in Settings). But when I relaunch my app the purchase still validates and my app displays the item as 'unlocked'. Figure the receipt must still be cached so I nuke the app and completely reinstall it but it appears StoreKit is still getting the receipt and it isn't being cleared because my app is displaying it as 'purchased.' Also tried rebooting the iPad. But the sandbox purchase doesn't clear. I just did a sandbox test since it is closer to real life than StoreKit Configuration so I just wanted to do it a few times to make sure all is good but making a burner test account for every purchase is kind of tiresome. Anyone know of a workaround? I might just declare victory and go back to StoreKit Configuration.
5
0
783
Jul ’26
Reply to How to manage TestFlight subscriptions on macOS?
If you are using TestFlight, then Sandbox would be used. To clear purchase history in sandbox please follow instructions in https://developer.apple.com/documentation/storekit/testing-in-app-purchases-with-sandbox#Clear-the-purchase-history-for-a-Sandbox-Apple-Account For me personally clearing purchase history didn't work https://developer.apple.com/forums/thread/829459 Please let me know if it works / doesn't work for you, thanks!
Topic: App & System Services SubTopic: StoreKit Tags:
Jul ’26
Reply to Mac App Store submission rejected for missing sandbox — but similar apps on the store don't use it
Your question is primarily about App Store policy. I don’t work for App Review and can’t offer definition answers about there policy. What I can say is that our documentation makes it clear that the Accessibility APIs are not supported in sandboxed apps. See the Review functionality that is incompatible with App Sandbox section of Protecting user data with App Sandbox. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Jul ’26
Reply to macOS Tahoe 26.5.1: Mac Catalyst App Crashes at Launch with EXC_BREAKPOINT in libsystem_secinit due to Container Integrity Check Failure
Is this affecting an app that you’ve built? Or are you seeing this with apps built by other developers? For context, the immediate cause of this crash is an app container ownership check. When a sandboxed app first launches, the system creates its app container and records information about the app’s identity into that container. The next time the app launches it checks that that this is the same app. This prevents a malicious app from impersonating some popular app and snarfing up its data. This “same app” check is based on code signing requirements. See TN3127 Inside Code Signing: Requirements. Something has gone wrong with that check in your case. I’m not aware of any specific reason why this check would suddenly start failing for your app. To understand what’s going on I’ll need a bunch of information from you, and hence the question above is the first of many (-: Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Topic: App & System Services SubTopic: Core OS Tags:
Jul ’26
Reply to Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
Thanks for looking into this. Re: timing — I can't give you a clean before/after-26.5 comparison. This specific NFS mount setup only went live on 2026-07-03, and I was already on 26.5.1/26.5.2 (25F84) at that point — so I have no data on this exact mount configuration under an earlier OS version. I did run a different mount method (SSHFS/macFUSE) at the same path before that, on earlier OS builds, but it failed differently (kext/Gatekeeper corruption), not with this deny(1) signature — so I can't say this is a regression tied to a specific OS version, only that it's new since I switched mount methods. Re: the StorageKit/r.171126338 log line — the timestamp you posted (2026-07-05 10:52:14+0200) lands within seconds of a deny(1) cluster I already captured a full sysdiagnose for (10:52:11–10:52:54, attached to FB23576006). I'll dig through that archive specifically for the StorageKit/SKManager entries around r.171126338 and report back what I find. Re: the workaround — good lead, and it lines up with something I
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jul ’26
Reply to Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
I'm seeing a recurring issue on macOS 26.5.2 (build 25F84) where the kernel's Sandbox/System Policy layer intermittently denies file access on NFS mount points from local network servers. Did this JUST start happening in 26.5? If not, do you know when it might have started? There was change at that time (r.171126338) which also introduced this error: 2026-07-05 10:52:14.292554+0200 diskutil: (StorageKit) [com.apple.storagekit:general] -[SKManager _diskForPath:isNetworkMount:]: open() failed: errno=1 I'm not sure how that would then connect to the failure you're seeing, but I think it might be connected to this. or has a workaround, So, the one thing I would try is moving the mount point out of /Users/Shared/ and into a location you more directly control- either a new directory in your home directory or a new directory you create within the system hierarchy. Creating your own directory helps shift you out of the systems normal view, which can reduce the possibility of unrelated activity disrupting you
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jul ’26
Reply to Supported way to use MapKit in a sandboxed macOS Quick Look extension?
@DTS Engineer I think your explanation is not entirely accurate. Actually the sandbox is already treating different system components differently. Therefore it seems very unlikely that the sandbox can not distinguish between allowed and forbidden network traffic. MapKit is an encapsulated system component, so it is more or less impossible for a Quicklook extension to send random and uncontrolled network requests. All the network access is completely controlled by the system. So it seems extremely unlikely that there are serious security issues here. BTW: in the past, MapKit did work in Quicklook extensions. On the other hand, WebKit (WKWebView) is(!) working in Quicklook extensions just fine. But unlike MapKit, WebKit is able to do random and uncontrolled network requests, therefore could be a security issue. Which means the sandbox is actually distinguishing between different system components. The harmless one it does block, the dangerous one it let pass. I do understand that WebK
Replies
Boosts
Views
Activity
Jul ’26
Reply to ShazamKit under the App Sandbox on macOS — sanctioned way to reach com.apple.shazamd? (error 202)
[quote='837008021, DANgerous25, /thread/837008, /profile/DANgerous25'] The iOS entitlement com.apple.developer.shazamkit is rejected by the macOS validator at upload [/quote] My undestanding is that this entitlement isn’t valid on iOS either. See here. [quote='837008021, DANgerous25, /thread/837008, /profile/DANgerous25'] Is it correct to place the exception on the main app … rather than on the helper itself? [/quote] That depends on how you run the helper. If you spawn it as a child process then it inherits your app’s static sandbox and thus adding entitlement to the parent app is the right choice. As to your main issue, am I right in assuming that this nested helper stuff isn’t a factor there? That is, the behaviour you’ve described applies regardless whether you run the code in your helper or in your main app? Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Topic: Media Technologies SubTopic: General Tags:
Replies
Boosts
Views
Activity
Jul ’26
Reply to In App Purchase Sandbox Testing - Clear Purchase History Not Working
I have same problem. There always a monthly subscrition . Can't clear by sandbox
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Jul ’26
How can a SwiftUI drag provide the actual file URL of an existing file on macOS (as NSOutlineView does)?
I'm dragging existing files from a SwiftUI List (a search result list in a sandboxed, document-based Mac app), and I want drop targets to receive the actual file URL — the same behavior as AppKit's NSOutlineView with outlineView(_:pasteboardWriterForItem:) returning an NSURL: the Finder copies the file, browsers load it, and text views insert its path. My current implementation is Transferable-based: FileRepresentation(exportedContentType: .data) { item in SentTransferredFile(item.fileURL, allowAccessingOriginalFile: true) } .suggestedFileName(.fileURL.lastPathComponent) With this, what receivers get is a temporary copy in the app's own container (Caches/com.apple.SwiftUI.Drag-/), not the actual file URL — despite allowAccessingOriginalFile: true. Dropping on the Finder or onto an application icon works through the copy, but receivers that interpret the URL itself — a browser window, or a text view that inserts the dropped file's path — see the temporary container path. Note that the dragged files li
Replies
3
Boosts
0
Views
661
Activity
Jul ’26
Kernel Sandbox/System Policy intermittently denies ALL file access (not just mount syscall) on NFS mounts
I'm seeing a recurring issue on macOS 26.5.2 (build 25F84) where the kernel's Sandbox/System Policy layer intermittently denies file access on NFS mount points from local network servers. Posting here in case anyone recognizes this pattern or has a workaround, and flagging it since I've also filed a Feedback Assistant report (with a live-captured sysdiagnose) for the same issue. WHAT HAPPENS Two independent NFS mounts to two separate, unrelated servers on my LAN start failing simultaneously with Operation not permitted. The kernel log shows: kernel: (Sandbox) System Policy: mount_nfs(PID) deny(1) file-mount /path/to/mount Critically, it's not limited to the mount syscall - within the same few-second window, System Policy also denies ls, perl, diskutil, and even umount -f on the exact same path, for otherwise unrelated processes. So it looks like a transient, path-scoped kernel decision rather than something specific to NFS or the mount syscall. It self-heals anywhere from seconds to ~30 minu
Replies
21
Boosts
0
Views
1.9k
Activity
Jul ’26
ShazamKit under the App Sandbox on macOS — sanctioned way to reach com.apple.shazamd? (error 202)
I'm building a music-recognition app for the Mac App Store that uses ShazamKit (SHSession / SHManagedSession) against the default Shazam catalog. In a sandboxed build, SHSession.match(_:) fails with: com.apple.ShazamKit error 202 — The connection to service named com.apple.shazamd was invalidated The root cause is a sandbox denial of the mach-lookup to the ShazamKit matching daemon: kernel (Sandbox): deny(1) mach-lookup com.apple.shazamd What I've established: Enabling the ShazamKit App Service on the App ID does not add com.apple.shazamd to the sandbox mach-lookup allow-list on macOS — the denial persists and matching returns error 202. The iOS entitlement com.apple.developer.shazamkit is rejected by the macOS validator at upload (not supported on macOS), so it isn't an option here. Adding com.apple.security.temporary-exception.mach-lookup.global-name = [com.apple.shazamd] to the app's entitlements removes the denial, and ShazamKit then matches correctly under the sandbox
Replies
5
Boosts
0
Views
1.1k
Activity
Jul ’26
Reply to unable to add sandbox mastercard to iwatch wallet
observed that mastercard from sandbox can be added with activating status. the card is activated after one day activating.
Replies
Boosts
Views
Activity
Jul ’26
How to share a keychain item between a mac os app and cli app
Hi, I would like to share a keychain item common for mac os app (sandboxed) and swift cli app (non sandboxed). Is there a recommended way for doing this? Thanks
Replies
1
Boosts
0
Views
427
Activity
Jul ’26
Cannot load products in Sandbox
Hi, I'm trying to hook up some test in app purchases to test purchase code between our app and our app's backend. When I try to load products (requestProductData) with my Sandbox account, my product identifiers come back in the invalid product identifiers member of the response. My product says it's in waiting for review status in app store connect, and I'm logged in to the app store with my sandbox account on my device. We just accepted the paid apps agreement as well--is there some propagation time to that? The product ID I'm using (both in app store connect and in-app) is test_durable. Do I need to append the package name to that or something? I've dug through the docs and through the forums here and come up empty. I tried using the Xcode storekit test harness and the issue there is that because that doesn't actually talk to the store apis, I can't use that to test my backend correctly validating/processing the transactions. Thanks!
Replies
0
Boosts
0
Views
466
Activity
Jul ’26
In App Purchase Sandbox Testing - Clear Purchase History Not Working
I'm testing iAP in a sandbox account (as configured in App Store Connect under 'Sandbox Testers'). So the in app purchase works. Cool. But I wanted to retry it. So I cleared the purchase history (both in App Store Connect and on my iPad in the 'Developer' section in Settings). But when I relaunch my app the purchase still validates and my app displays the item as 'unlocked'. Figure the receipt must still be cached so I nuke the app and completely reinstall it but it appears StoreKit is still getting the receipt and it isn't being cleared because my app is displaying it as 'purchased.' Also tried rebooting the iPad. But the sandbox purchase doesn't clear. I just did a sandbox test since it is closer to real life than StoreKit Configuration so I just wanted to do it a few times to make sure all is good but making a burner test account for every purchase is kind of tiresome. Anyone know of a workaround? I might just declare victory and go back to StoreKit Configuration.
Replies
5
Boosts
0
Views
783
Activity
Jul ’26
Reply to How to manage TestFlight subscriptions on macOS?
If you are using TestFlight, then Sandbox would be used. To clear purchase history in sandbox please follow instructions in https://developer.apple.com/documentation/storekit/testing-in-app-purchases-with-sandbox#Clear-the-purchase-history-for-a-Sandbox-Apple-Account For me personally clearing purchase history didn't work https://developer.apple.com/forums/thread/829459 Please let me know if it works / doesn't work for you, thanks!
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Jul ’26
Reply to Mac App Store submission rejected for missing sandbox — but similar apps on the store don't use it
Your question is primarily about App Store policy. I don’t work for App Review and can’t offer definition answers about there policy. What I can say is that our documentation makes it clear that the Accessibility APIs are not supported in sandboxed apps. See the Review functionality that is incompatible with App Sandbox section of Protecting user data with App Sandbox. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Replies
Boosts
Views
Activity
Jul ’26
Reply to macOS Tahoe 26.5.1: Mac Catalyst App Crashes at Launch with EXC_BREAKPOINT in libsystem_secinit due to Container Integrity Check Failure
Is this affecting an app that you’ve built? Or are you seeing this with apps built by other developers? For context, the immediate cause of this crash is an app container ownership check. When a sandboxed app first launches, the system creates its app container and records information about the app’s identity into that container. The next time the app launches it checks that that this is the same app. This prevents a malicious app from impersonating some popular app and snarfing up its data. This “same app” check is based on code signing requirements. See TN3127 Inside Code Signing: Requirements. Something has gone wrong with that check in your case. I’m not aware of any specific reason why this check would suddenly start failing for your app. To understand what’s going on I’ll need a bunch of information from you, and hence the question above is the first of many (-: Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jul ’26