Search results for

“sandbox”

10,542 results found

Post

Replies

Boosts

Views

Activity

Reply to Promo Code and Offers
Hello, If you have already configured your IAPs and offers in App Store Connect, you can build and run your app on a physical device and test in the Sandbox environment (note that this requires logging in with a Sandbox account). If you prefer to use the simulator instead, check out StoreKit Testing in Xcode: https://developer.apple.com/documentation/xcode/setting-up-storekit-testing-in-xcode. This allows you to setup a local test environment for testing your IAPs (including offers). You can set up a StoreKit configuration file manually, or have it sync with your App Store Connect account so you can test with the same data you have already configured. If you have any questions regarding this setup, don't hesitate to ask.
Topic: StoreKit SubTopic:
StoreKit, In-App Purchase, and App Store Server API Q&A
Jun ’26
Testing purchases Advanced Commerce API
Hello! Is it possible to test in Sandbox the flow of pending purchase request changes to succeed for Advanced Commerce API? As StoreKit configuration file can not be used with Advanced Commerce API, how to test for example flow Ask to Buy when child account ask parent account to buy generic consumable product? And also does Advanced Commerce API supports feature Ask to Buy?
2
0
341
Jun ’26
Request for Escalation – Non-Reproducible StoreKit Failure During App Review
Dear Apple Developer Support and App Review Team, I am contacting you regarding a recurring issue that has prevented my application from successfully passing App Review despite extensive testing and multiple attempts to investigate and resolve the problem. The application has been rejected under Guideline 2.1 – Performance because the subscription plans reportedly fail to load during review. According to the review notes, the In-App Purchase product list appears empty on the review device, preventing the paywall from displaying correctly. The main challenge is that this behavior cannot be reproduced outside of the App Review environment. The exact same binary reviewed by App Review has been thoroughly tested through TestFlight on multiple physical iPhone and iPad devices using multiple Sandbox tester accounts, different network conditions, fresh installations, and repeated purchase cycles. In every test, StoreKit successfully retrieves the configured products, RevenueCat offerings load correctly, loc
1
0
291
Jun ’26
How to Sandbox SwiftData Edits in .sheet
Is this the right way to pass data to a sheet for editing? struct Detail: View { ... // The single atomic source of truth for our sheet presentation @State var editorConfig: EditorConfig? // Completely encapsulated local configuration package struct EditorConfig: Identifiable { var id: PersistentIdentifier { item.persistentModelID } let context: ModelContext let item: Item } var body: some View { ... Button(Edit) { // 1. Spin up a separate scratchpad container layer let context = ModelContext(modelContext.container) context.autosaveEnabled = false // 2. Safely resolve our model inside the new isolated playground if let sandboxItem = context.model(for: item.persistentModelID) as? Item { // 3. Package it up to trigger the sheet presentation editorConfig = EditorConfig(context: context, item: sandboxItem) } } } } // 4. SwiftUI tracks value replacement accurately without ghost state bugs .sheet(item: $editorConfig) { config in // Inject the isolated context into the sheet's environment chain EditorView(item: conf
Topic: UI Frameworks SubTopic: SwiftUI
1
0
190
Jun ’26
Is there a public API or entitlement for a user-controlled Apple Pencil annotation overlay across iPadOS apps?
Hello, I am exploring an iPadOS product idea for Apple Pencil users and would like to understand the current public API boundary. The user need is a temporary, user-controlled Apple Pencil annotation layer while the user is working in another app or workspace. For example, a student may be reading in Books, Safari, a PDF app, or another educational app and want to write quick Pencil notes directly over the visible material without taking a screenshot or exporting the content first. I understand that PencilKit works inside an app's own UI, and I also understand that iPadOS sandboxing prevents third-party apps from inspecting or modifying other apps. I am not trying to bypass that model. What I am trying to determine is: Is there any current public API, extension point, or entitlement that allows a user-initiated Apple Pencil overlay session across the current iPadOS workspace? If not, is Feedback Assistant the right place to request a new PencilKit / iPadOS entitlement for this use case? Are there exi
1
0
1.1k
Jun ’26
Reply to OpenZFS on FSKit — Proof of Concept
Kevin, thank you for the detailed responses — this is exactly the kind of clarity we were hoping for. Let me work through your points. On app-sandbox=true The reframe is helpful. We were reading sandbox as locked down rather than opt-in capability declaration. That makes much more sense architecturally. The practical follow-on question: what entitlements exist today for block device ioctls (DKIOCGETBLOCKSIZE, DKIOCGETBLOCKCOUNT)? We currently work around their absence with a path→size registry, but if we can simply declare the entitlement, that's the right fix. Similarly for any IPC socket path we'd use for the management layer. On the management plane Good news: we already implemented a UNIX socket approach — a zfsd management daemon that receives ZFS_IOC_* requests over a socket, paired with a libzfs_core transport that connects to it instead of opening /dev/zfs. The open question is whether the sandboxed extension can create and bind a socket at a path reachable by privileged too
Topic: App & System Services SubTopic: Core OS Tags:
Jun ’26
Reply to FUSE compat surface plans?
I've submitted Feedback FB23056342, whose text follows. This Feedback captures my response in forum topic https://developer.apple.com/forums/thread/831338?answerId=891228022#891228022 to the request by Apple Staff to detail obstacles that FSKit may have to FUSE3 compatibility, quoted here: A FUSE compatibility layer on top of FSKit represents an excellent 3rd-party opportunity. We are definitely interested in any feedback related to obstacles in developing such a compatibility layer. First, thank you. This is a helpful dialog. We maintain a production network filesystem with a FUSE3-based implementation for Linux. We also implement this filesystem with a XNU VNOP-based kernel extension implementation for macOS. We are highly motivated to move our macOS implementation into user space (via FSKit), but we see gaps in FSKit that prevent compatible implementation to match the capabilities afforded by either the XNU VNOP or FUSE3 interface. We are not asking Apple to publish a FUSE3 shim (though that would be nice)
Topic: Core OS SubTopic:
File Systems Q&A
Tags:
Jun ’26
Reply to Is there some tutorial for the new `es_new_descendants_client` function?
First, I thought it would be good to monitor processes I launch from my central application - but I won't fork() or exec() other apps - I will ask launchd to open them (NSWorkspace...), so they won't be descendants of my Endpoint Security client containing process. It's tied to your direct child processes (the whole process subtree derived from you), but that doesn't mean you couldn't restrict an app. We don't encourage it but, in practice, apps created through fork/exec basically work fine. Not to mention, I don't understand how this aligns with the entitlement being attachable only to system(?) extensions. The entitlement isn't restricted to system extensions and never has been. There is a system extension point, but that primarily exists so that ES clients can get control of the system as EARLY as possible (basically, before ANY 3rd party executes). The extension point is actually used less often than you'd think, as most ES clients are actually just LaunchDaemons. Similarly: Or, can I now add this entitle
Topic: App & System Services SubTopic: Core OS Tags:
Jun ’26
Sandbox-Bypassing IPC between App Intents and Launchd Daemons on macOS
We are designing a macOS utility that runs a local background agent via launchd (managing a local SQLite database and Unix socket). We want to expose controls (start/stop, status checks, CLI command invocation) to Siri via the App Intents framework. Since App Intents typically execute within a sandboxed App Extension or a sandboxed App wrapper container: What is the recommended IPC mechanism (e.g., Unix domain sockets, local HTTP/TCP ports, XPC) to securely communicate between a sandboxed App Intent extension and a non-sandboxed launchd helper daemon on macOS? Are there specific Entitlements (com.apple.security.temporary-exception.files.absolute-path.read-write or network exceptions) required to allow App Intents to talk to local UNIX sockets or loopback interfaces (127.0.0.1) without triggering sandbox violations? Can an App Intent directly invoke a helper command-line tool or launch a plist-configured service without bringing up the main application UI?
2
0
409
Jun ’26
Code sharing between targets and what’s the best structure for doing so
I guess this is in parts a multiplatform / SwiftData / WidgetKit and SwiftUI question. my usual problem is I start an app and then quickly find myself wanting to add widgets / controls / AppIntents and expand across multiple targets. for example I start with an iOS only target and expand to watchOS, iPadOS and visionOS. But since this targets and the apps I want to build are very distinct, I don’t find myself using the multiplatform target but instead a target per platform. This (at least from my understanding) then also comes with the benefit that I can add a WidgetKit extension and all targets use it. now this is the base idea, but here come the many questions I have had issues finding a clear answer and guidance on over the last years. When sharing SwiftUI views and business logic for DRY, whats the actual best way to do that? A „core“ swift package, or a library? what are the implications of choosing one over the other? I understand that widgets are separately scoped and sandboxed from my main ap
1
0
155
Jun ’26
Reply to Bookmarks and network remounting
In my sandboxed app, if a bookmarked network source is unavailable, is resolving the source/root security-scoped bookmark the recommended way to trigger a remount of the network volume? Yes, that's generally the best option. It's obviously not guaranteed to work, given all of the possible failure cases, but it covers the largest number of edge cases with the least amount of work. The other alternative would be to use the NetFS framework to directly mount the volume; however, I think that really only makes sense if/when your app is designed around that approach. Are you having problems with bookmark mount resolution? __ Kevin Elliott DTS Engineer, CoreOS/Hardware
Topic: Core OS SubTopic:
File Systems Q&A
Tags:
Jun ’26
Can FSClient.mountSingleVolume be used for block devices?
Can the new FSClient.mountSingleVolume along with the com.apple.developer.fskit.mount entitlement be used to mount a block device resource from a sandboxed GUI app? I ask since FSBlockDeviceResource doesn’t seem to have a public initializer other than init(coder:) and using Disk Arbitration (e.g. DADiskMount or DADiskMountWithArguments) has been finicky with the App Sandbox (FB16728800). I'm interested in making an easy workaround e.g. for users who have an internal partition supported by my file system extension that isn't automounting (FB21729650).
3
0
698
Jun ’26
Reply to Promo Code and Offers
Hello, If you have already configured your IAPs and offers in App Store Connect, you can build and run your app on a physical device and test in the Sandbox environment (note that this requires logging in with a Sandbox account). If you prefer to use the simulator instead, check out StoreKit Testing in Xcode: https://developer.apple.com/documentation/xcode/setting-up-storekit-testing-in-xcode. This allows you to setup a local test environment for testing your IAPs (including offers). You can set up a StoreKit configuration file manually, or have it sync with your App Store Connect account so you can test with the same data you have already configured. If you have any questions regarding this setup, don't hesitate to ask.
Topic: StoreKit SubTopic:
StoreKit, In-App Purchase, and App Store Server API Q&A
Replies
Boosts
Views
Activity
Jun ’26
Testing purchases Advanced Commerce API
Hello! Is it possible to test in Sandbox the flow of pending purchase request changes to succeed for Advanced Commerce API? As StoreKit configuration file can not be used with Advanced Commerce API, how to test for example flow Ask to Buy when child account ask parent account to buy generic consumable product? And also does Advanced Commerce API supports feature Ask to Buy?
Replies
2
Boosts
0
Views
341
Activity
Jun ’26
Request for Escalation – Non-Reproducible StoreKit Failure During App Review
Dear Apple Developer Support and App Review Team, I am contacting you regarding a recurring issue that has prevented my application from successfully passing App Review despite extensive testing and multiple attempts to investigate and resolve the problem. The application has been rejected under Guideline 2.1 – Performance because the subscription plans reportedly fail to load during review. According to the review notes, the In-App Purchase product list appears empty on the review device, preventing the paywall from displaying correctly. The main challenge is that this behavior cannot be reproduced outside of the App Review environment. The exact same binary reviewed by App Review has been thoroughly tested through TestFlight on multiple physical iPhone and iPad devices using multiple Sandbox tester accounts, different network conditions, fresh installations, and repeated purchase cycles. In every test, StoreKit successfully retrieves the configured products, RevenueCat offerings load correctly, loc
Replies
1
Boosts
0
Views
291
Activity
Jun ’26
How to Sandbox SwiftData Edits in .sheet
Is this the right way to pass data to a sheet for editing? struct Detail: View { ... // The single atomic source of truth for our sheet presentation @State var editorConfig: EditorConfig? // Completely encapsulated local configuration package struct EditorConfig: Identifiable { var id: PersistentIdentifier { item.persistentModelID } let context: ModelContext let item: Item } var body: some View { ... Button(Edit) { // 1. Spin up a separate scratchpad container layer let context = ModelContext(modelContext.container) context.autosaveEnabled = false // 2. Safely resolve our model inside the new isolated playground if let sandboxItem = context.model(for: item.persistentModelID) as? Item { // 3. Package it up to trigger the sheet presentation editorConfig = EditorConfig(context: context, item: sandboxItem) } } } } // 4. SwiftUI tracks value replacement accurately without ghost state bugs .sheet(item: $editorConfig) { config in // Inject the isolated context into the sheet's environment chain EditorView(item: conf
Topic: UI Frameworks SubTopic: SwiftUI
Replies
1
Boosts
0
Views
190
Activity
Jun ’26
Is there a public API or entitlement for a user-controlled Apple Pencil annotation overlay across iPadOS apps?
Hello, I am exploring an iPadOS product idea for Apple Pencil users and would like to understand the current public API boundary. The user need is a temporary, user-controlled Apple Pencil annotation layer while the user is working in another app or workspace. For example, a student may be reading in Books, Safari, a PDF app, or another educational app and want to write quick Pencil notes directly over the visible material without taking a screenshot or exporting the content first. I understand that PencilKit works inside an app's own UI, and I also understand that iPadOS sandboxing prevents third-party apps from inspecting or modifying other apps. I am not trying to bypass that model. What I am trying to determine is: Is there any current public API, extension point, or entitlement that allows a user-initiated Apple Pencil overlay session across the current iPadOS workspace? If not, is Feedback Assistant the right place to request a new PencilKit / iPadOS entitlement for this use case? Are there exi
Replies
1
Boosts
0
Views
1.1k
Activity
Jun ’26
Reply to OpenZFS on FSKit — Proof of Concept
Kevin, thank you for the detailed responses — this is exactly the kind of clarity we were hoping for. Let me work through your points. On app-sandbox=true The reframe is helpful. We were reading sandbox as locked down rather than opt-in capability declaration. That makes much more sense architecturally. The practical follow-on question: what entitlements exist today for block device ioctls (DKIOCGETBLOCKSIZE, DKIOCGETBLOCKCOUNT)? We currently work around their absence with a path→size registry, but if we can simply declare the entitlement, that's the right fix. Similarly for any IPC socket path we'd use for the management layer. On the management plane Good news: we already implemented a UNIX socket approach — a zfsd management daemon that receives ZFS_IOC_* requests over a socket, paired with a libzfs_core transport that connects to it instead of opening /dev/zfs. The open question is whether the sandboxed extension can create and bind a socket at a path reachable by privileged too
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jun ’26
Reply to FUSE compat surface plans?
I've submitted Feedback FB23056342, whose text follows. This Feedback captures my response in forum topic https://developer.apple.com/forums/thread/831338?answerId=891228022#891228022 to the request by Apple Staff to detail obstacles that FSKit may have to FUSE3 compatibility, quoted here: A FUSE compatibility layer on top of FSKit represents an excellent 3rd-party opportunity. We are definitely interested in any feedback related to obstacles in developing such a compatibility layer. First, thank you. This is a helpful dialog. We maintain a production network filesystem with a FUSE3-based implementation for Linux. We also implement this filesystem with a XNU VNOP-based kernel extension implementation for macOS. We are highly motivated to move our macOS implementation into user space (via FSKit), but we see gaps in FSKit that prevent compatible implementation to match the capabilities afforded by either the XNU VNOP or FUSE3 interface. We are not asking Apple to publish a FUSE3 shim (though that would be nice)
Topic: Core OS SubTopic:
File Systems Q&A
Tags:
Replies
Boosts
Views
Activity
Jun ’26
Sandboxed network permissions on macOS
Are there specific Entitlements (com.apple.security.temporary-exception.files.absolute-path.read-write or network exceptions) required to allow App Intents to talk to local UNIX sockets or loopback interfaces (127.0.0.1) without triggering sandbox violations?
Replies
1
Boosts
0
Views
758
Activity
Jun ’26
Reply to Is there some tutorial for the new `es_new_descendants_client` function?
First, I thought it would be good to monitor processes I launch from my central application - but I won't fork() or exec() other apps - I will ask launchd to open them (NSWorkspace...), so they won't be descendants of my Endpoint Security client containing process. It's tied to your direct child processes (the whole process subtree derived from you), but that doesn't mean you couldn't restrict an app. We don't encourage it but, in practice, apps created through fork/exec basically work fine. Not to mention, I don't understand how this aligns with the entitlement being attachable only to system(?) extensions. The entitlement isn't restricted to system extensions and never has been. There is a system extension point, but that primarily exists so that ES clients can get control of the system as EARLY as possible (basically, before ANY 3rd party executes). The extension point is actually used less often than you'd think, as most ES clients are actually just LaunchDaemons. Similarly: Or, can I now add this entitle
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jun ’26
Reply to Sandbox-Bypassing IPC between App Intents and Launchd Daemons on macOS
How to handle loopback network permissions and Unix socket restrictions that block sandboxed App Extensions from talking to localhost?
Topic: App Intents SubTopic:
App Intents & Siri Q&A
Replies
Boosts
Views
Activity
Jun ’26
Sandbox-Bypassing IPC between App Intents and Launchd Daemons on macOS
We are designing a macOS utility that runs a local background agent via launchd (managing a local SQLite database and Unix socket). We want to expose controls (start/stop, status checks, CLI command invocation) to Siri via the App Intents framework. Since App Intents typically execute within a sandboxed App Extension or a sandboxed App wrapper container: What is the recommended IPC mechanism (e.g., Unix domain sockets, local HTTP/TCP ports, XPC) to securely communicate between a sandboxed App Intent extension and a non-sandboxed launchd helper daemon on macOS? Are there specific Entitlements (com.apple.security.temporary-exception.files.absolute-path.read-write or network exceptions) required to allow App Intents to talk to local UNIX sockets or loopback interfaces (127.0.0.1) without triggering sandbox violations? Can an App Intent directly invoke a helper command-line tool or launch a plist-configured service without bringing up the main application UI?
Replies
2
Boosts
0
Views
409
Activity
Jun ’26
Code sharing between targets and what’s the best structure for doing so
I guess this is in parts a multiplatform / SwiftData / WidgetKit and SwiftUI question. my usual problem is I start an app and then quickly find myself wanting to add widgets / controls / AppIntents and expand across multiple targets. for example I start with an iOS only target and expand to watchOS, iPadOS and visionOS. But since this targets and the apps I want to build are very distinct, I don’t find myself using the multiplatform target but instead a target per platform. This (at least from my understanding) then also comes with the benefit that I can add a WidgetKit extension and all targets use it. now this is the base idea, but here come the many questions I have had issues finding a clear answer and guidance on over the last years. When sharing SwiftUI views and business logic for DRY, whats the actual best way to do that? A „core“ swift package, or a library? what are the implications of choosing one over the other? I understand that widgets are separately scoped and sandboxed from my main ap
Replies
1
Boosts
0
Views
155
Activity
Jun ’26
Reply to Bookmarks and network remounting
In my sandboxed app, if a bookmarked network source is unavailable, is resolving the source/root security-scoped bookmark the recommended way to trigger a remount of the network volume? Yes, that's generally the best option. It's obviously not guaranteed to work, given all of the possible failure cases, but it covers the largest number of edge cases with the least amount of work. The other alternative would be to use the NetFS framework to directly mount the volume; however, I think that really only makes sense if/when your app is designed around that approach. Are you having problems with bookmark mount resolution? __ Kevin Elliott DTS Engineer, CoreOS/Hardware
Topic: Core OS SubTopic:
File Systems Q&A
Tags:
Replies
Boosts
Views
Activity
Jun ’26
Bookmarks and network remounting
In my sandboxed app, if a bookmarked network source is unavailable, is resolving the source/root security-scoped bookmark the recommended way to way to trigger a remount of the network volume? Thanks!
Replies
2
Boosts
0
Views
540
Activity
Jun ’26
Can FSClient.mountSingleVolume be used for block devices?
Can the new FSClient.mountSingleVolume along with the com.apple.developer.fskit.mount entitlement be used to mount a block device resource from a sandboxed GUI app? I ask since FSBlockDeviceResource doesn’t seem to have a public initializer other than init(coder:) and using Disk Arbitration (e.g. DADiskMount or DADiskMountWithArguments) has been finicky with the App Sandbox (FB16728800). I'm interested in making an easy workaround e.g. for users who have an internal partition supported by my file system extension that isn't automounting (FB21729650).
Replies
3
Boosts
0
Views
698
Activity
Jun ’26