Search results for

“sandbox”

10,542 results found

Post

Replies

Boosts

Views

Activity

In App Purchases constantly rejected
We've got our first app developed currently stuck in a loop with AppStore Review. And we are getting no where. After no shows from calls with the team someone finally got back to me but after they had the team really try we have made no progress. We have subscriptions to use the app and then a further subscription to turn on a local web server. We have been able to purchase both (in each of their modes, monthly,annually, annually-monthly, outright) via test flight THOUSANDS of times. App Store Review have never been able to see the purchases. They keep sending general 'you need to turn on StoreKit' 'you need to configure AppStore API' But I dont think that we do? Its very strange that we can ue the IAP's perfectly but when we submit they cannot be seen. We keep going through this cycle: Create IAPS. set them up in our app Test them locally (using sandbox from Xcode) Deploy via test flight to other machines. Do in app purchases absolutely no problem. Submit binary+add IAPS (this sets them into awaitin
1
0
214
Jun ’26
Reply to Single Build / Archive for iOS and Catalyst Build
Thanks for your question, I suggest you do two separate Build and Archive processes, one for iOS and one for Mac Catalyst. What version of Xcode are you using? Even though Mac Catalyst allows you to use a single codebase and a single Xcode project, the end result is two completely different binaries. I would recommend to use Xcode 27.0 beta X You can also create a multiple platform and then add Mac Catalyst: “For Mac Catalyst builds, this target and its dependencies will link or embed only Mac-compatible content, and the security and App Sandbox settings will be aligned with the iOS app.” Only one native Mac app can be added to the App Store, so make sure you select a Mac Catalyst or a Designed for iPad. If you have Apple Vision on that multi platform will be superseded by the native Apple Vision app in the App Store. You achieve this by ensuring that both your iOS target and your Mac Catalyst target use the exact same Bundle Identifier. Once your Catalyst app is approved and released, it will be the
Jun ’26
Testing Revoke App Consent
Hi, I have two questions: Is there any way to test the revoke consent flow on a local build of our app? When I try using Sandbox to Revoke App Consent with the application bundle ID of a locally built and deployed app, it fails with Cannot Trigger Notification. The bundle ID you provided is invalid or you do not have access to the app. https://developer.apple.com/support/age-assurance/#responsibility states that When a parent or guardian revokes consent for their child to access an app, Apple will prevent the app from launching. However, when using the Sandbox to revoke app consent, the app is still launchable. Does anyone know if the app being launchable is exclusive to Sandbox, and how this works in prouduction?
0
0
448
Jun ’26
API to determine firewall settings in sandboxed app
My app is sandboxed and for one feature listens for an incoming connection on a user selected port. When the firewall is enabled and block incoming (all, this app, or signed apps) is enabled, I want to be able to not offer this feature with a brief explanation. I tried using /usr/libexec/ApplicationFirewall/socketfilterfw but that fails when used in a sandboxed app. I have an XPC module, which is also sandboxed, and the call fails there as well. If I remove the sandbox from the XPC then the call succeeds but then is unable to communicate with the main app. Is there an API to determine if the firewall is enabled and all connections blocked? I've submitted a Feedback request (FB23378402) as well.
1
0
809
Jun ’26
[NetworkExtension] [EndpointSecurity] [AppStore] [macOS] Can an app that uses a MitM-style network traffic interception be submitted to the AppStore?
Hello, What are the restrictions on submitting apps to the mac App Store that use an NETransparentProxy alongside a locally installed and trusted Root-CA to intercept, decrypt and manipulate TLS traffic? To be more specific, I'm not talking about a Safari extension. I'm talking about system-wide traffic. So that the app can detect and block ads and trackers from all apps, not just Safari. I'm aware that such an app can be distributed using an unsandboxed Developer-ID signed app. But I wonder if such an app also breaks Sandbox requirements for AppStore distributed apps? Also, is there a way for a sandboxed app to install and trust a root CA? SecTrustSettingsSetTrustSettings does not work in Sandboxed apps from what I found. Finally, I want to ask about EndpointSecurity. Can this entitlement be used in AppStore-ditributed apps? Is doing any of these things possible on AppStore-distributed apps? Thanks in advance for your reply.
2
0
1.2k
Jun ’26
Reply to Location Services stopped working across the system on macOS
hanks for the post. This is extremely interesting post. Since you have already ruled out the network environment (by testing multiple Wi-Fi networks and an iPhone hotspot) and user-space configurations, the issue is almost certainly occurring at the daemon level, the network-request level, or is a beta-specific hardware? The correct thing to do should be to filing a bug with a focused simple project showing the issue because at this time I do not think we have seen that issue happening as far as I know. While you mentioned resetting Location Services, macOS can be notoriously stubborn about holding onto corrupted SQLite databases in the /var/db/locationd/ directory. If the local cache is corrupted, locationd might fail to write new ALS responses or read existing ones, defaulting to an unknown state. Location Services can intentionally fail to return a location if the Wi-Fi interface is missing a Country Code or is receiving conflicting 802.11d regulatory domain beacons. In some beta builds, if the system cann
Jun ’26
StoreKit returns 0 subscription products in Sandbox/TestFlight — payment sheet never opens (auto-renewable subscriptions)
Hello, I'm developing a consumer iOS app (Capacitor + RevenueCat SDK) and I've been blocked for several weeks on a StoreKit issue: subscription products are never returned to the device, so the Apple payment sheet cannot open. I previously contacted Apple Support. I was told to request a phone call, but my call request was declined because of the topic (StoreKit / in-app purchases). I'm posting here hoping someone from Apple or the community can help. App details App name: Vytal AI Bundle ID: com.ciborgu.vytalai App Store Connect App ID: 6767160542 Team ID: JZF7CR3W8Z Distribution: TestFlight (physical iPhone, France) iOS deployment target: 15+ Subscription product IDs (auto-renewable) vytalai_premium_monthly vytalai_premium_yearly vytalai_premium_yearly_intro All three are in subscription group Vytal AI on the correct ASC app (not a typo bundle). Cleared for Sale is ON. Paid Apps Agreement is active. In-App Purchase capability is enabled on the App ID (checkbox is grayed out / locked, which I understand is n
1
0
1.3k
Jun ’26
Reply to Updating App - Validation Hell - 90286, 91130
[quote='894813022, DrMiller, /thread/835497?answerId=894813022#894813022, /profile/DrMiller'] 346JXXXXXX is my Team Member ID [/quote] No it isn’t. Rather, it’s your App ID prefix. That much is very clear from my view of your team, but you can prove it for yourself. Do this: Go to the Certificates, Identifiers, and Profiles section of the Developer website Switch to Identifiers. Filter for App IDs containing com.company.app-name (well, your real bundle ID, not the redacted one we’re using here). Open the one you find. At the top right you’ll see your Team ID and in the App ID Prefix field you’ll see your… well… App ID prefix. Here’s an example of what that looks like for an App ID in one of the DTS test teams: If you manually generate a provisioning profile for that App ID and then dump that profile you’ll see something like this: % security cms -D -i AppIDPrefixTest_Mac_Dev.provisionprofile | plutil -p - { … ApplicationIdentifierPrefix => [ 0 => VYRRC68ZE6 ] … Entitlements => { com.apple.application
Jun ’26
Reply to S5 - Specific Siri Security Situation in Slovakia
Dears, Several days have passed ... More than 30 developers have seen this, yet nobody replied to me. Please understand that this is not my day job. I have purchased a PERSONAL PRODUCTION version a NEW Macbook M4 air 15inch 2025 together with iPhone 17 standard 2025 in Slovakia as explained above. Yet my macbook and my iphone are setup as an AppleInternal devices with experimental functions and some really important files that I probably should not see .... So please get me somebody to whom I can talk to !!! I guess this is somekind of a leakage that somehow ended in my hands ... There is a lot here, but I dont want to share in forum ..... Some details from my terminal ... echo $PATH /usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/local/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/appleinternal/bin:/pkg/env/global/bin Here are som
Jun ’26
Apple-signed Production transactions return 404 (4040010) on every App Store Server API endpoint
Environment: Production. Bundle ID: com.filmixpro.filmix. (Team ID / notification URL available privately or via Feedback Assistant.) We received 7 App Store Server Notifications V2 (SUBSCRIBED) whose JWS signatures we successfully verified against Apple root CAs (decoded payloads show environment=Production, bundleId=com.filmixpro.filmix). However, querying the App Store Server API (production) for these originalTransactionIds returns 404 (4040010) Transaction id not found on EVERY endpoint: Get All Subscription Statuses, Get Transaction Info, Get Transaction History, Get Refund History, and Get Notification History (filtered by transactionId). The same API key resolves all other transactions correctly (these are 7 out of 3231 chains scanned). The IDs are also absent from the global Get Notification History (last 180 days). Sandbox returns 404 as well. One of them, 520002039865757, previously generated a REFUND_DECLINED notification (a refund was requested and DECLINED — i.e. not refunded), yet it t
1
0
653
Jun ’26
Reply to SwiftData, CloudKit and 2 AppleIDs
I found out part of my problem involving CloudKit, SwiftData and multiple AppleIDs. It turns out that there is a setting in the Mac version of the AppStore app, called Sandbox Account. (This setting is not available on the Mobile versions of the AppStore app.) It appears that this setting is used to determine what AppleID is associated with an app when it is downloaded. In my case, this setting was set to my old AppleID. So when I loaded my app from the AppStore, it was associated with my old AppleID, which meant that CloudKit stored its synced data is my old AppleID's account. On the mobile side, this setting doesn't exist, so it appears that the AppStore uses the CURRENT AppleID. So my app was associated with one AppleID on the Macintosh and another AppleID on mobile devices. Hence incompatible data and no syncing. Changing this setting on Macintosh and reloading fixes synching, but leaves me with a different problem — before starting all this testing, I saved the SwiftData database from the Mac, w
Jun ’26
StoreKit returns 0 subscriptions on TestFlight — Apple IAP payment sheet never opens (Capacitor + RevenueCat)
Hello, I'm developing a Capacitor/Next.js iOS app with RevenueCat for auto-renewable subscriptions. On a real iPhone via TestFlight, StoreKit never returns my subscription products, so the Apple payment sheet never appears. App TestFlight builds tested: 110, 111, 112 (iOS 1.1.0) In-App Purchase capability enabled on App ID Paid Applications Agreement: active Banking/tax: active Subscription product IDs (auto-renewable, same subscription group) vytalai_premium_monthly vytalai_premium_yearly vytalai_premium_yearly_intro (exit offer) What happens Install app from TestFlight on physical iPhone Navigate to paywall App calls RevenueCat → Purchases.getProducts() with the 3 product IDs above StoreKit returns 0 products (or configure/getProducts times out) UI shows: Apple Store: 0 subscriptions on this device — Sandbox popup cannot open Tapping subscribe does not open the Apple payment sheet Fallback prices appear (3.49 / 29.99) instead of live App Store prices (3,49 € / 29,99 €), which suggests StoreKit is n
2
0
819
Jun ’26
Reply to Programmatic IP Discovery for VZVirtualMachine in an App Store Sandbox
I took the help of claude code and come to a conclusion like this Summary: IPv4 ARP cache invisible via PF_ROUTE sysctl on macOS 27 — bundled apps only; cause unknown TL;DR: On macOS 27, querying the IPv4 ARP cache via sysctl(CTL_NET, PF_ROUTE, 0, AF_INET, NET_RT_FLAGS, RTF_LLINFO) returns an empty result (needed == 0) inside our built .app bundle, with or without the App Sandbox entitlement. The identical query with AF_INET6 returns real data in the same app. arp -a (system binary) shows IPv4 entries fine. Crucially, the identical sysctl code run as a bare, unbundled swift repro.swift script also returns real IPv4 data — so this is not about code-signing or sandboxing in general, it's specific to being a launched, bundled GUI app. We suspected the Local Network privacy permission next (the app had never appeared in System Settings → Privacy & Security → Local Network), added NSLocalNetworkUsageDescription/NSBonjourServices, forced the permission prompt via an NWBrowser Bonjour browse, a
Topic: App & System Services SubTopic: Core OS Tags:
Jun ’26
In App Purchases constantly rejected
We've got our first app developed currently stuck in a loop with AppStore Review. And we are getting no where. After no shows from calls with the team someone finally got back to me but after they had the team really try we have made no progress. We have subscriptions to use the app and then a further subscription to turn on a local web server. We have been able to purchase both (in each of their modes, monthly,annually, annually-monthly, outright) via test flight THOUSANDS of times. App Store Review have never been able to see the purchases. They keep sending general 'you need to turn on StoreKit' 'you need to configure AppStore API' But I dont think that we do? Its very strange that we can ue the IAP's perfectly but when we submit they cannot be seen. We keep going through this cycle: Create IAPS. set them up in our app Test them locally (using sandbox from Xcode) Deploy via test flight to other machines. Do in app purchases absolutely no problem. Submit binary+add IAPS (this sets them into awaitin
Replies
1
Boosts
0
Views
214
Activity
Jun ’26
Reply to Single Build / Archive for iOS and Catalyst Build
Thanks for your question, I suggest you do two separate Build and Archive processes, one for iOS and one for Mac Catalyst. What version of Xcode are you using? Even though Mac Catalyst allows you to use a single codebase and a single Xcode project, the end result is two completely different binaries. I would recommend to use Xcode 27.0 beta X You can also create a multiple platform and then add Mac Catalyst: “For Mac Catalyst builds, this target and its dependencies will link or embed only Mac-compatible content, and the security and App Sandbox settings will be aligned with the iOS app.” Only one native Mac app can be added to the App Store, so make sure you select a Mac Catalyst or a Designed for iPad. If you have Apple Vision on that multi platform will be superseded by the native Apple Vision app in the App Store. You achieve this by ensuring that both your iOS target and your Mac Catalyst target use the exact same Bundle Identifier. Once your Catalyst app is approved and released, it will be the
Replies
Boosts
Views
Activity
Jun ’26
Testing Revoke App Consent
Hi, I have two questions: Is there any way to test the revoke consent flow on a local build of our app? When I try using Sandbox to Revoke App Consent with the application bundle ID of a locally built and deployed app, it fails with Cannot Trigger Notification. The bundle ID you provided is invalid or you do not have access to the app. https://developer.apple.com/support/age-assurance/#responsibility states that When a parent or guardian revokes consent for their child to access an app, Apple will prevent the app from launching. However, when using the Sandbox to revoke app consent, the app is still launchable. Does anyone know if the app being launchable is exclusive to Sandbox, and how this works in prouduction?
Replies
0
Boosts
0
Views
448
Activity
Jun ’26
API to determine firewall settings in sandboxed app
My app is sandboxed and for one feature listens for an incoming connection on a user selected port. When the firewall is enabled and block incoming (all, this app, or signed apps) is enabled, I want to be able to not offer this feature with a brief explanation. I tried using /usr/libexec/ApplicationFirewall/socketfilterfw but that fails when used in a sandboxed app. I have an XPC module, which is also sandboxed, and the call fails there as well. If I remove the sandbox from the XPC then the call succeeds but then is unable to communicate with the main app. Is there an API to determine if the firewall is enabled and all connections blocked? I've submitted a Feedback request (FB23378402) as well.
Replies
1
Boosts
0
Views
809
Activity
Jun ’26
[NetworkExtension] [EndpointSecurity] [AppStore] [macOS] Can an app that uses a MitM-style network traffic interception be submitted to the AppStore?
Hello, What are the restrictions on submitting apps to the mac App Store that use an NETransparentProxy alongside a locally installed and trusted Root-CA to intercept, decrypt and manipulate TLS traffic? To be more specific, I'm not talking about a Safari extension. I'm talking about system-wide traffic. So that the app can detect and block ads and trackers from all apps, not just Safari. I'm aware that such an app can be distributed using an unsandboxed Developer-ID signed app. But I wonder if such an app also breaks Sandbox requirements for AppStore distributed apps? Also, is there a way for a sandboxed app to install and trust a root CA? SecTrustSettingsSetTrustSettings does not work in Sandboxed apps from what I found. Finally, I want to ask about EndpointSecurity. Can this entitlement be used in AppStore-ditributed apps? Is doing any of these things possible on AppStore-distributed apps? Thanks in advance for your reply.
Replies
2
Boosts
0
Views
1.2k
Activity
Jun ’26
Reply to Location Services stopped working across the system on macOS
hanks for the post. This is extremely interesting post. Since you have already ruled out the network environment (by testing multiple Wi-Fi networks and an iPhone hotspot) and user-space configurations, the issue is almost certainly occurring at the daemon level, the network-request level, or is a beta-specific hardware? The correct thing to do should be to filing a bug with a focused simple project showing the issue because at this time I do not think we have seen that issue happening as far as I know. While you mentioned resetting Location Services, macOS can be notoriously stubborn about holding onto corrupted SQLite databases in the /var/db/locationd/ directory. If the local cache is corrupted, locationd might fail to write new ALS responses or read existing ones, defaulting to an unknown state. Location Services can intentionally fail to return a location if the Wi-Fi interface is missing a Country Code or is receiving conflicting 802.11d regulatory domain beacons. In some beta builds, if the system cann
Replies
Boosts
Views
Activity
Jun ’26
StoreKit returns 0 subscription products in Sandbox/TestFlight — payment sheet never opens (auto-renewable subscriptions)
Hello, I'm developing a consumer iOS app (Capacitor + RevenueCat SDK) and I've been blocked for several weeks on a StoreKit issue: subscription products are never returned to the device, so the Apple payment sheet cannot open. I previously contacted Apple Support. I was told to request a phone call, but my call request was declined because of the topic (StoreKit / in-app purchases). I'm posting here hoping someone from Apple or the community can help. App details App name: Vytal AI Bundle ID: com.ciborgu.vytalai App Store Connect App ID: 6767160542 Team ID: JZF7CR3W8Z Distribution: TestFlight (physical iPhone, France) iOS deployment target: 15+ Subscription product IDs (auto-renewable) vytalai_premium_monthly vytalai_premium_yearly vytalai_premium_yearly_intro All three are in subscription group Vytal AI on the correct ASC app (not a typo bundle). Cleared for Sale is ON. Paid Apps Agreement is active. In-App Purchase capability is enabled on the App ID (checkbox is grayed out / locked, which I understand is n
Replies
1
Boosts
0
Views
1.3k
Activity
Jun ’26
StoreKit problem
StoreKit getProducts returns 0 subscriptions on TestFlight for product IDs vytalai_premium_monthly, vytalai_premium_yearly, vytalai_premium_yearly_intro (bundle com.ciborgu.vytalai, build 112+). All metadata submitted, Paid Apps Agreement active. Please check why Sandbox catalog is empty for this app.
Replies
1
Boosts
0
Views
757
Activity
Jun ’26
Reply to Updating App - Validation Hell - 90286, 91130
[quote='894813022, DrMiller, /thread/835497?answerId=894813022#894813022, /profile/DrMiller'] 346JXXXXXX is my Team Member ID [/quote] No it isn’t. Rather, it’s your App ID prefix. That much is very clear from my view of your team, but you can prove it for yourself. Do this: Go to the Certificates, Identifiers, and Profiles section of the Developer website Switch to Identifiers. Filter for App IDs containing com.company.app-name (well, your real bundle ID, not the redacted one we’re using here). Open the one you find. At the top right you’ll see your Team ID and in the App ID Prefix field you’ll see your… well… App ID prefix. Here’s an example of what that looks like for an App ID in one of the DTS test teams: If you manually generate a provisioning profile for that App ID and then dump that profile you’ll see something like this: % security cms -D -i AppIDPrefixTest_Mac_Dev.provisionprofile | plutil -p - { … ApplicationIdentifierPrefix => [ 0 => VYRRC68ZE6 ] … Entitlements => { com.apple.application
Replies
Boosts
Views
Activity
Jun ’26
Reply to Push provisioning failing.
also unable to add sandbox mastercard to iwatch wallet, no issue for amex. slightly difficult and failed but in the end managed to add visa after several manual input sandbox test card. Please take a look at 23315137
Topic: App & System Services SubTopic: Wallet Tags:
Replies
Boosts
Views
Activity
Jun ’26
Reply to S5 - Specific Siri Security Situation in Slovakia
Dears, Several days have passed ... More than 30 developers have seen this, yet nobody replied to me. Please understand that this is not my day job. I have purchased a PERSONAL PRODUCTION version a NEW Macbook M4 air 15inch 2025 together with iPhone 17 standard 2025 in Slovakia as explained above. Yet my macbook and my iphone are setup as an AppleInternal devices with experimental functions and some really important files that I probably should not see .... So please get me somebody to whom I can talk to !!! I guess this is somekind of a leakage that somehow ended in my hands ... There is a lot here, but I dont want to share in forum ..... Some details from my terminal ... echo $PATH /usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/local/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/appleinternal/bin:/pkg/env/global/bin Here are som
Replies
Boosts
Views
Activity
Jun ’26
Apple-signed Production transactions return 404 (4040010) on every App Store Server API endpoint
Environment: Production. Bundle ID: com.filmixpro.filmix. (Team ID / notification URL available privately or via Feedback Assistant.) We received 7 App Store Server Notifications V2 (SUBSCRIBED) whose JWS signatures we successfully verified against Apple root CAs (decoded payloads show environment=Production, bundleId=com.filmixpro.filmix). However, querying the App Store Server API (production) for these originalTransactionIds returns 404 (4040010) Transaction id not found on EVERY endpoint: Get All Subscription Statuses, Get Transaction Info, Get Transaction History, Get Refund History, and Get Notification History (filtered by transactionId). The same API key resolves all other transactions correctly (these are 7 out of 3231 chains scanned). The IDs are also absent from the global Get Notification History (last 180 days). Sandbox returns 404 as well. One of them, 520002039865757, previously generated a REFUND_DECLINED notification (a refund was requested and DECLINED — i.e. not refunded), yet it t
Replies
1
Boosts
0
Views
653
Activity
Jun ’26
Reply to SwiftData, CloudKit and 2 AppleIDs
I found out part of my problem involving CloudKit, SwiftData and multiple AppleIDs. It turns out that there is a setting in the Mac version of the AppStore app, called Sandbox Account. (This setting is not available on the Mobile versions of the AppStore app.) It appears that this setting is used to determine what AppleID is associated with an app when it is downloaded. In my case, this setting was set to my old AppleID. So when I loaded my app from the AppStore, it was associated with my old AppleID, which meant that CloudKit stored its synced data is my old AppleID's account. On the mobile side, this setting doesn't exist, so it appears that the AppStore uses the CURRENT AppleID. So my app was associated with one AppleID on the Macintosh and another AppleID on mobile devices. Hence incompatible data and no syncing. Changing this setting on Macintosh and reloading fixes synching, but leaves me with a different problem — before starting all this testing, I saved the SwiftData database from the Mac, w
Replies
Boosts
Views
Activity
Jun ’26
StoreKit returns 0 subscriptions on TestFlight — Apple IAP payment sheet never opens (Capacitor + RevenueCat)
Hello, I'm developing a Capacitor/Next.js iOS app with RevenueCat for auto-renewable subscriptions. On a real iPhone via TestFlight, StoreKit never returns my subscription products, so the Apple payment sheet never appears. App TestFlight builds tested: 110, 111, 112 (iOS 1.1.0) In-App Purchase capability enabled on App ID Paid Applications Agreement: active Banking/tax: active Subscription product IDs (auto-renewable, same subscription group) vytalai_premium_monthly vytalai_premium_yearly vytalai_premium_yearly_intro (exit offer) What happens Install app from TestFlight on physical iPhone Navigate to paywall App calls RevenueCat → Purchases.getProducts() with the 3 product IDs above StoreKit returns 0 products (or configure/getProducts times out) UI shows: Apple Store: 0 subscriptions on this device — Sandbox popup cannot open Tapping subscribe does not open the Apple payment sheet Fallback prices appear (3.49 / 29.99) instead of live App Store prices (3,49 € / 29,99 €), which suggests StoreKit is n
Replies
2
Boosts
0
Views
819
Activity
Jun ’26
Reply to Programmatic IP Discovery for VZVirtualMachine in an App Store Sandbox
I took the help of claude code and come to a conclusion like this Summary: IPv4 ARP cache invisible via PF_ROUTE sysctl on macOS 27 — bundled apps only; cause unknown TL;DR: On macOS 27, querying the IPv4 ARP cache via sysctl(CTL_NET, PF_ROUTE, 0, AF_INET, NET_RT_FLAGS, RTF_LLINFO) returns an empty result (needed == 0) inside our built .app bundle, with or without the App Sandbox entitlement. The identical query with AF_INET6 returns real data in the same app. arp -a (system binary) shows IPv4 entries fine. Crucially, the identical sysctl code run as a bare, unbundled swift repro.swift script also returns real IPv4 data — so this is not about code-signing or sandboxing in general, it's specific to being a launched, bundled GUI app. We suspected the Local Network privacy permission next (the app had never appeared in System Settings → Privacy & Security → Local Network), added NSLocalNetworkUsageDescription/NSBonjourServices, forced the permission prompt via an NWBrowser Bonjour browse, a
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jun ’26