Search results for

“sandbox”

10,540 results found

Post

Replies

Boosts

Views

Activity

Sandbox Visa test card refused at provisioning (403) on supervised iPhones only; Mastercard fails at eligibility (500) everywhere
We test Apple Pay in the sandbox on supervised iPhones in a device lab (Apple Configurator supervision, no MDM enrollment, no SIM, iOS 26.x). Since late September two of the test cards from the Sandbox Testing page no longer add to Wallet. Discover test cards still add fine on the same devices and accounts. Filed as FB24994276 (Visa) and FB24994258 (Mastercard), with device logs and timestamps. Visa 4622 9431 2318 9285 (FB24994276), only on our lab devices: eligibility → 412 → TSM sync → 200, received eligibility status: 1 terms shown and accepted provision → HTTP 403 → PKProvisioningErrorDomain Code=3 → Invalid Card Same result on two different lab iPhones, including one signed in to a brand-new sandbox account. The same new account and the same card add successfully on an unsupervised iPhone on a home network (iOS 18.2.1). Neither side sends location data. Mastercard 5204 2452 5046 0049 (FB24994258), on every device we tried, lab and home, iOS 18.2.1 and 26.x: eligibility → 412 →
0
0
88
1w
App Store Server API: Sandbox 200, Production 401 with same JWT
App Store Server API: Sandbox returns 200, Production returns 401 with the same JWT We are seeing a reproducible authentication issue with the App Store Server API for our app FYRT. Bundle ID: com.fyrt.Fyrt We performed a fresh read-only test on September 29, 2026 using our In-App Purchase key BJ5HR5GSY6. Both requests used: the same In-App Purchase key the same Issuer ID the same Bundle ID ES256 the same JWT structure 300-second token lifetime correct system time with no relevant clock skew Only the environment changed. Sandbox: HTTP 200 Apple Request ID: 458b3b32-8e0d-1404-19fe-6c92ba2ccd27 Production: HTTP 401 Apple Request ID: 193406ac-80d2-d135-8cc8-34e4ebe76fc5 The Production response does not include an additional Apple error code. The request is read-only and requests notification history. No purchase is triggered and no Production data is changed. We verified: correct Key ID correct Issuer ID correct Bundle ID ES256 signing current iat valid exp correct Sandbox and Producti
0
0
85
1w
Reply to Sandboxed helper keeps running after the app is turned off in Background App Activity
Thanks, Quinn. It depends on the setup: In the reproducer from the post, it's a fixed file inside the app bundle: /Applications/.app/Contents/Library/LaunchAgents/.plist, bootstrapped by that absolute path. In our current build, the daemon writes it at each start to /var/run/.plist (owned by root, mode 0600) and bootstraps that file. Its ProgramArguments point at the nested helper inside the app bundle: /Applications/.app/Contents/Helpers/.app/Contents/MacOS/. We generate it because it passes the app's build number as an argument; that could move into the helper itself. We can use whichever location you'd consider least fragile. What we're really after is both App Sandbox and a dedicated non-root identity for the helper, before login, since it parses untrusted input. Is there a supported way to get both? If not, we'd pick one of two configurations that already work for us. Which would you consider on firmer ground? SMAppService.daemon running as root, with App Sandbox. SMAppService.daemon wi
1w
Reply to macOS content filter: supported denial guarantee across provider failure for a bounded process tree
[quote='907201022, JMartell, /thread/848507?answerId=907201022#907201022, /profile/JMartell'] the requirement is to deny all network access [/quote] Have you thoughts about achieving that by enabling App Sandbox? That is, have your top-level process enabled App Sandbox (claim com.apple.security.app-sandbox) and then not enable networking (that is, claim neither com.apple.security.network.client nor com.apple.security.network.server). This might be easier because blocking networking at the NE level requires you to accurately track responsibility, which can be quite challenging. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
1w
Reply to StoreKit Product Retrieval Issue During App Review
Bonjour, J'ai reçu cela et ça fait plus de 2 mois que nous sommes dessus et nous n'arrivons pas à avoir l'approbation d'Apple alors que quand nous testons l'application, tout fonctionne bien. Guideline 2.1(b) - Performance - App Completeness Issue Description The In-App Purchase products in the app exhibited one or more bugs which create a poor user experience. Specifically, your app failed to display the prices and displayed an error message when we tried to make a purchase. Review the details and resources below to troubleshoot this issue. Review device details: Device type: iPad Air 11-inch (M3) OS version: iPadOS 27.0 Next Steps Apple reviews In-App Purchase products in the sandbox and the In-App Purchase products do not need prior approval to function in review. Review the product configurations, complete any missing information, and test them in the sandbox. To offer In-App Purchases in the app, implement the StoreKit framework and the Account Holder must also accept the Paid Apps Agre
Topic: StoreKit SubTopic:
StoreKit, In-App Purchase, and App Store Server API Q&A
1w
Reply to Sandboxed macOS dictation: insert at the current focused input across apps
[quote='848711021, maxpaleo, /thread/848711, /profile/maxpaleo'] is there any supported sandbox-compatible way to know whether the destination has a focused editable field or is a secure input, or to learn whether a posted paste was actually accepted? [/quote] No. Hmmmm, except for the secure event input thing. Last I checked you can detect the system-wide secure event input state via IsSecureEventInputEnabled, and that works in a sandboxed app. However, there’s no supported way to determine which app has enabled it, and I’m not sure whether the unsupported way — which is commonly used but also quite unreliable — will work in a sandboxed app. [quote='848711021, maxpaleo, /thread/848711, /profile/maxpaleo'] is relying on the destination app’s paste handling and retaining the transcript for manual recovery the expected approach? [/quote] That’s more of a question for you than for me, in that it’s not a question about Apple APIs but about the overall user experience of your product. Sh
Topic: UI Frameworks SubTopic: General Tags:
1w
Reply to macOS content filter: supported denial guarantee across provider failure for a bounded process tree
Thank you, Quinn. For the bounded offline operation in this question, the requirement is to deny all network access, rather than selectively allow or inspect destinations. The scope is the operation's supervisor, controller and helper, including network requests attributable to them through delegated system services. Unrelated applications on the Mac should retain their normal network access. The restriction must apply before releasing any of these processes and remain effective until the processes and attributable delegated work are quiescent. In particular, a filtering-provider crash, disconnect, hang or restart must not open a temporary network-access window. Does that clarification point to a supported macOS mechanism for this scope, including whether individually sandboxing the roles without network entitlements provides the needed independent boundary? We are asking about a supported design; we have not established or claimed that our current implementation provides this guarantee.
1w
Sandboxed helper keeps running after the app is turned off in Background App Activity
Short version: we run a sandboxed helper as a hidden service account, started at boot by an SMAppService daemon. It works, even before login. But when the user turns our app off in Background App Activity, only the daemon stops. The helper keeps running. Is this setup supported, and what's the right way to manage the helper? What we want A Developer ID signed, notarized app (not Mac App Store) with a helper that parses untrusted input. The helper should: run as a dedicated, hidden, non-login local account; use App Sandbox, with its own container; be available before anyone logs in (after FileVault unlock). What we built An unsandboxed root LaunchDaemon, registered with SMAppService.daemon, runs this at boot: launchctl bootstrap user/ The agent plist uses LimitLoadToSessionType=Background. The helper is a nested app in the same bundle, with com.apple.security.app-sandbox=true. We don't create a GUI session, change UID after the sandbox starts, or use private APIs. What we m
6
0
290
1w
Sandboxed macOS dictation: insert at the current focused input across apps
Update: I clarified the intended behavior after posting. The destination is the text input that has keyboard focus when the finished dictation is delivered, even if the user changed fields or apps while speaking. We do not need to return to the field where dictation started. I’m building a macOS dictation app for the Mac App Store, so it must run with App Sandbox enabled. For example, a user might start dictating with an input in Chrome focused, then click into a ChatGPT input while speaking. When the result is ready, it should insert at the ChatGPT caret. Moving the caret within one app should likewise change the destination. In an isolated signed sandboxed prototype, I write a marker to the general pasteboard and post Command–V with CGEvent.post after the user grants event-posting access. This inserts successfully in TextEdit at the current caret, including after a same-document caret move. That result is now consistent with the intended behavior. The prototype also has a frontmost-process
1
0
317
1w
Questions on App Store Server API behaviors: Production accounts in Sandbox, and Cleared Sandbox data
Hello, I would like to clarify the exact technical behavior of the App Store Server API (V2) and StoreKit under the following two specific scenarios: Case A (Production Account on Sandbox Endpoint): If a user with a production Apple Account attempts to purchase through a build pointing to the Apple Sandbox environment (or Sandbox API), how does the Apple server handle this transaction and its data lifecycle? (Does StoreKit block this at the client-side, or does the API return a specific error code?) Case B (Restoring Cleared Sandbox Data): If a Sandbox tester's purchase history is cleared/deleted on the Apple server, and the app subsequently requests a Restore Purchase or queries the App Store Server API using a previously valid transactionID from that account, what specific error code (such as 4040010 TransactionNotFound) or empty response does the Apple server return? I would highly appreciate your confirmation or any technical insights on these behaviors. Thank
1
0
234
1w
Best practices for backend server transition timing to Production App Store Server API
Hello, I would like to clarify the best practices and timing for our backend server to transition its main connection to the production App Store Server API. Currently, we are considering the following approach: We plan to switch our backend’s primary API endpoint from Sandbox to Production once our app passes the App Store review and its status changes to Ready for Sale. Could you please confirm if this timing is standard and correct? Additionally, to handle App Store reviews (which run in the Sandbox environment) and TestFlight tests seamlessly without manual configuration changes, we are planning to implement an automatic fallback mechanism: Our backend always requests the Production App Store Server API first. If it returns a TransactionNotFound (e.g., 4040010) error, the backend automatically retries the request using the Sandbox API. Is this automatic fallback from Production to Sandbox considered a safe and recommended practice by Apple, especially for App Store revi
0
0
87
1w
Is dynamic fallback to Sandbox API correct when receiving error 4040010 (TransactionIdNotFoundError) during App Review?
Hi, During the App Review process, a test purchase was made using what appeared to be a production Apple account. When our app server sent this transactionId to the Production App Store Server API, it returned the error code 4040010 (TransactionIdNotFoundError). To handle this gracefully and prevent review rejections, we are considering implementing a dynamic fallback mechanism on our app server. Specifically, when the Production API returns 4040010, the server will automatically retry the request using the Sandbox App Store Server API URL. Could you please clarify the following points regarding this design? Is it expected behavior for an App Review purchase to return 4040010 on the Production API, and can it be successfully verified by routing it to the Sandbox API? Is this dynamic fallback logic (Production API ➔ if 4040010 ➔ Sandbox API) a recommended and officially supported best practice for handling App Review and TestFlight transactions? Any confirmation or advice from Apple
0
0
55
1w
Is transactionId unique across Production and Sandbox environments for DB design?
Hi, I am designing a database schema to store App Store transaction data for our backend system, and I have a question regarding the uniqueness of transactionId. According to the documentation (apple.com), transactionId is a unique identifier for a transaction. However, it is not explicitly clear whether this uniqueness is guaranteed across different environments.Could you please clarify the following points? Is transactionId guaranteed to be unique across both the Production and Sandbox environments? (i.e., Is there any possibility that the exact same transactionId is generated in both environments?) For database design, is it safe to use transactionId alone as a Primary Key? Or is it strongly recommended to use a composite key consisting of both environment and transactionId? Any insights or best practices from Apple engineers or the community would be highly appreciated.Thank you.
1
0
339
1w
Supported macOS confinement for a supervised process tree
I am evaluating a local diagnostic design before implementation or deployment and need to identify a public, supported macOS confinement mechanism. Proposed arrangement: A privileged custodian remains outside a separate privileged guardian's process group. The guardian launches a fixed diagnostic parent under a dedicated unprivileged identity. That parent sequentially launches three fixed sandboxed Python workloads, one child at a time. The current termination design targets the guardian's process group. It must not rely on whole-host process scans or indiscriminate killing. The proposed sandbox profiles are allow-default with file/network restrictions; the test-child profiles deny process-fork. We have not established that these restrictions prevent an existing process from changing its own group or session. Is there a public, supported interface or configuration that keeps all workload descendants within the supervisor's termination boundary from the initial child transition through final
0
0
127
1w
Software volume for HDMI/DisplayPort outputs via process taps works; requesting a native option (FB24965962)
HDMI and DisplayPort audio devices expose no kAudioDevicePropertyVolumeScalar or kAudioDevicePropertyMute, so System Settings disables the volume slider and the media keys do nothing when such a display is the default output. Users end up installing virtual audio drivers or DDC/CI tools, and DDC does not pass through many HDMI paths at all. I wanted to check whether the behavior users expect can be provided with public API only, and it can: AudioHardwareCreateProcessTap with a CATapDescription that excludes the app's own process and uses CATapMutedWhenTapped, a private aggregate device with the tap as a sub-tap and the display as the main sub-device, and an IOProc that scales the tap input into the device output. The volume keys are captured with a session-level CGEvent tap. Source (three files, Swift and Objective-C): https://github.com/mevlut-geredeli/MonitorKeys Observations that may be useful to others using taps: The tap delivers IOProc callbacks only while some process is rendering; at idle there are no
0
0
272
1w
Sandbox Visa test card refused at provisioning (403) on supervised iPhones only; Mastercard fails at eligibility (500) everywhere
We test Apple Pay in the sandbox on supervised iPhones in a device lab (Apple Configurator supervision, no MDM enrollment, no SIM, iOS 26.x). Since late September two of the test cards from the Sandbox Testing page no longer add to Wallet. Discover test cards still add fine on the same devices and accounts. Filed as FB24994276 (Visa) and FB24994258 (Mastercard), with device logs and timestamps. Visa 4622 9431 2318 9285 (FB24994276), only on our lab devices: eligibility → 412 → TSM sync → 200, received eligibility status: 1 terms shown and accepted provision → HTTP 403 → PKProvisioningErrorDomain Code=3 → Invalid Card Same result on two different lab iPhones, including one signed in to a brand-new sandbox account. The same new account and the same card add successfully on an unsupervised iPhone on a home network (iOS 18.2.1). Neither side sends location data. Mastercard 5204 2452 5046 0049 (FB24994258), on every device we tried, lab and home, iOS 18.2.1 and 26.x: eligibility → 412 →
Replies
0
Boosts
0
Views
88
Activity
1w
App Store Server API: Sandbox 200, Production 401 with same JWT
App Store Server API: Sandbox returns 200, Production returns 401 with the same JWT We are seeing a reproducible authentication issue with the App Store Server API for our app FYRT. Bundle ID: com.fyrt.Fyrt We performed a fresh read-only test on September 29, 2026 using our In-App Purchase key BJ5HR5GSY6. Both requests used: the same In-App Purchase key the same Issuer ID the same Bundle ID ES256 the same JWT structure 300-second token lifetime correct system time with no relevant clock skew Only the environment changed. Sandbox: HTTP 200 Apple Request ID: 458b3b32-8e0d-1404-19fe-6c92ba2ccd27 Production: HTTP 401 Apple Request ID: 193406ac-80d2-d135-8cc8-34e4ebe76fc5 The Production response does not include an additional Apple error code. The request is read-only and requests notification history. No purchase is triggered and no Production data is changed. We verified: correct Key ID correct Issuer ID correct Bundle ID ES256 signing current iat valid exp correct Sandbox and Producti
Replies
0
Boosts
0
Views
85
Activity
1w
Reply to Sandboxed helper keeps running after the app is turned off in Background App Activity
Thanks, Quinn. It depends on the setup: In the reproducer from the post, it's a fixed file inside the app bundle: /Applications/.app/Contents/Library/LaunchAgents/.plist, bootstrapped by that absolute path. In our current build, the daemon writes it at each start to /var/run/.plist (owned by root, mode 0600) and bootstraps that file. Its ProgramArguments point at the nested helper inside the app bundle: /Applications/.app/Contents/Helpers/.app/Contents/MacOS/. We generate it because it passes the app's build number as an argument; that could move into the helper itself. We can use whichever location you'd consider least fragile. What we're really after is both App Sandbox and a dedicated non-root identity for the helper, before login, since it parses untrusted input. Is there a supported way to get both? If not, we'd pick one of two configurations that already work for us. Which would you consider on firmer ground? SMAppService.daemon running as root, with App Sandbox. SMAppService.daemon wi
Replies
Boosts
Views
Activity
1w
Reply to macOS content filter: supported denial guarantee across provider failure for a bounded process tree
[quote='907201022, JMartell, /thread/848507?answerId=907201022#907201022, /profile/JMartell'] the requirement is to deny all network access [/quote] Have you thoughts about achieving that by enabling App Sandbox? That is, have your top-level process enabled App Sandbox (claim com.apple.security.app-sandbox) and then not enable networking (that is, claim neither com.apple.security.network.client nor com.apple.security.network.server). This might be easier because blocking networking at the NE level requires you to accurately track responsibility, which can be quite challenging. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Replies
Boosts
Views
Activity
1w
Reply to StoreKit Product Retrieval Issue During App Review
Bonjour, J'ai reçu cela et ça fait plus de 2 mois que nous sommes dessus et nous n'arrivons pas à avoir l'approbation d'Apple alors que quand nous testons l'application, tout fonctionne bien. Guideline 2.1(b) - Performance - App Completeness Issue Description The In-App Purchase products in the app exhibited one or more bugs which create a poor user experience. Specifically, your app failed to display the prices and displayed an error message when we tried to make a purchase. Review the details and resources below to troubleshoot this issue. Review device details: Device type: iPad Air 11-inch (M3) OS version: iPadOS 27.0 Next Steps Apple reviews In-App Purchase products in the sandbox and the In-App Purchase products do not need prior approval to function in review. Review the product configurations, complete any missing information, and test them in the sandbox. To offer In-App Purchases in the app, implement the StoreKit framework and the Account Holder must also accept the Paid Apps Agre
Topic: StoreKit SubTopic:
StoreKit, In-App Purchase, and App Store Server API Q&A
Replies
Boosts
Views
Activity
1w
Reply to Sandboxed macOS dictation: insert at the current focused input across apps
[quote='848711021, maxpaleo, /thread/848711, /profile/maxpaleo'] is there any supported sandbox-compatible way to know whether the destination has a focused editable field or is a secure input, or to learn whether a posted paste was actually accepted? [/quote] No. Hmmmm, except for the secure event input thing. Last I checked you can detect the system-wide secure event input state via IsSecureEventInputEnabled, and that works in a sandboxed app. However, there’s no supported way to determine which app has enabled it, and I’m not sure whether the unsupported way — which is commonly used but also quite unreliable — will work in a sandboxed app. [quote='848711021, maxpaleo, /thread/848711, /profile/maxpaleo'] is relying on the destination app’s paste handling and retaining the transcript for manual recovery the expected approach? [/quote] That’s more of a question for you than for me, in that it’s not a question about Apple APIs but about the overall user experience of your product. Sh
Topic: UI Frameworks SubTopic: General Tags:
Replies
Boosts
Views
Activity
1w
Reply to macOS content filter: supported denial guarantee across provider failure for a bounded process tree
Thank you, Quinn. For the bounded offline operation in this question, the requirement is to deny all network access, rather than selectively allow or inspect destinations. The scope is the operation's supervisor, controller and helper, including network requests attributable to them through delegated system services. Unrelated applications on the Mac should retain their normal network access. The restriction must apply before releasing any of these processes and remain effective until the processes and attributable delegated work are quiescent. In particular, a filtering-provider crash, disconnect, hang or restart must not open a temporary network-access window. Does that clarification point to a supported macOS mechanism for this scope, including whether individually sandboxing the roles without network entitlements provides the needed independent boundary? We are asking about a supported design; we have not established or claimed that our current implementation provides this guarantee.
Replies
Boosts
Views
Activity
1w
Sandboxed helper keeps running after the app is turned off in Background App Activity
Short version: we run a sandboxed helper as a hidden service account, started at boot by an SMAppService daemon. It works, even before login. But when the user turns our app off in Background App Activity, only the daemon stops. The helper keeps running. Is this setup supported, and what's the right way to manage the helper? What we want A Developer ID signed, notarized app (not Mac App Store) with a helper that parses untrusted input. The helper should: run as a dedicated, hidden, non-login local account; use App Sandbox, with its own container; be available before anyone logs in (after FileVault unlock). What we built An unsandboxed root LaunchDaemon, registered with SMAppService.daemon, runs this at boot: launchctl bootstrap user/ The agent plist uses LimitLoadToSessionType=Background. The helper is a nested app in the same bundle, with com.apple.security.app-sandbox=true. We don't create a GUI session, change UID after the sandbox starts, or use private APIs. What we m
Replies
6
Boosts
0
Views
290
Activity
1w
Sandboxed macOS dictation: insert at the current focused input across apps
Update: I clarified the intended behavior after posting. The destination is the text input that has keyboard focus when the finished dictation is delivered, even if the user changed fields or apps while speaking. We do not need to return to the field where dictation started. I’m building a macOS dictation app for the Mac App Store, so it must run with App Sandbox enabled. For example, a user might start dictating with an input in Chrome focused, then click into a ChatGPT input while speaking. When the result is ready, it should insert at the ChatGPT caret. Moving the caret within one app should likewise change the destination. In an isolated signed sandboxed prototype, I write a marker to the general pasteboard and post Command–V with CGEvent.post after the user grants event-posting access. This inserts successfully in TextEdit at the current caret, including after a same-document caret move. That result is now consistent with the intended behavior. The prototype also has a frontmost-process
Replies
1
Boosts
0
Views
317
Activity
1w
Questions on App Store Server API behaviors: Production accounts in Sandbox, and Cleared Sandbox data
Hello, I would like to clarify the exact technical behavior of the App Store Server API (V2) and StoreKit under the following two specific scenarios: Case A (Production Account on Sandbox Endpoint): If a user with a production Apple Account attempts to purchase through a build pointing to the Apple Sandbox environment (or Sandbox API), how does the Apple server handle this transaction and its data lifecycle? (Does StoreKit block this at the client-side, or does the API return a specific error code?) Case B (Restoring Cleared Sandbox Data): If a Sandbox tester's purchase history is cleared/deleted on the Apple server, and the app subsequently requests a Restore Purchase or queries the App Store Server API using a previously valid transactionID from that account, what specific error code (such as 4040010 TransactionNotFound) or empty response does the Apple server return? I would highly appreciate your confirmation or any technical insights on these behaviors. Thank
Replies
1
Boosts
0
Views
234
Activity
1w
Best practices for backend server transition timing to Production App Store Server API
Hello, I would like to clarify the best practices and timing for our backend server to transition its main connection to the production App Store Server API. Currently, we are considering the following approach: We plan to switch our backend’s primary API endpoint from Sandbox to Production once our app passes the App Store review and its status changes to Ready for Sale. Could you please confirm if this timing is standard and correct? Additionally, to handle App Store reviews (which run in the Sandbox environment) and TestFlight tests seamlessly without manual configuration changes, we are planning to implement an automatic fallback mechanism: Our backend always requests the Production App Store Server API first. If it returns a TransactionNotFound (e.g., 4040010) error, the backend automatically retries the request using the Sandbox API. Is this automatic fallback from Production to Sandbox considered a safe and recommended practice by Apple, especially for App Store revi
Replies
0
Boosts
0
Views
87
Activity
1w
Is dynamic fallback to Sandbox API correct when receiving error 4040010 (TransactionIdNotFoundError) during App Review?
Hi, During the App Review process, a test purchase was made using what appeared to be a production Apple account. When our app server sent this transactionId to the Production App Store Server API, it returned the error code 4040010 (TransactionIdNotFoundError). To handle this gracefully and prevent review rejections, we are considering implementing a dynamic fallback mechanism on our app server. Specifically, when the Production API returns 4040010, the server will automatically retry the request using the Sandbox App Store Server API URL. Could you please clarify the following points regarding this design? Is it expected behavior for an App Review purchase to return 4040010 on the Production API, and can it be successfully verified by routing it to the Sandbox API? Is this dynamic fallback logic (Production API ➔ if 4040010 ➔ Sandbox API) a recommended and officially supported best practice for handling App Review and TestFlight transactions? Any confirmation or advice from Apple
Replies
0
Boosts
0
Views
55
Activity
1w
Is transactionId unique across Production and Sandbox environments for DB design?
Hi, I am designing a database schema to store App Store transaction data for our backend system, and I have a question regarding the uniqueness of transactionId. According to the documentation (apple.com), transactionId is a unique identifier for a transaction. However, it is not explicitly clear whether this uniqueness is guaranteed across different environments.Could you please clarify the following points? Is transactionId guaranteed to be unique across both the Production and Sandbox environments? (i.e., Is there any possibility that the exact same transactionId is generated in both environments?) For database design, is it safe to use transactionId alone as a Primary Key? Or is it strongly recommended to use a composite key consisting of both environment and transactionId? Any insights or best practices from Apple engineers or the community would be highly appreciated.Thank you.
Replies
1
Boosts
0
Views
339
Activity
1w
Supported macOS confinement for a supervised process tree
I am evaluating a local diagnostic design before implementation or deployment and need to identify a public, supported macOS confinement mechanism. Proposed arrangement: A privileged custodian remains outside a separate privileged guardian's process group. The guardian launches a fixed diagnostic parent under a dedicated unprivileged identity. That parent sequentially launches three fixed sandboxed Python workloads, one child at a time. The current termination design targets the guardian's process group. It must not rely on whole-host process scans or indiscriminate killing. The proposed sandbox profiles are allow-default with file/network restrictions; the test-child profiles deny process-fork. We have not established that these restrictions prevent an existing process from changing its own group or session. Is there a public, supported interface or configuration that keeps all workload descendants within the supervisor's termination boundary from the initial child transition through final
Replies
0
Boosts
0
Views
127
Activity
1w
Software volume for HDMI/DisplayPort outputs via process taps works; requesting a native option (FB24965962)
HDMI and DisplayPort audio devices expose no kAudioDevicePropertyVolumeScalar or kAudioDevicePropertyMute, so System Settings disables the volume slider and the media keys do nothing when such a display is the default output. Users end up installing virtual audio drivers or DDC/CI tools, and DDC does not pass through many HDMI paths at all. I wanted to check whether the behavior users expect can be provided with public API only, and it can: AudioHardwareCreateProcessTap with a CATapDescription that excludes the app's own process and uses CATapMutedWhenTapped, a private aggregate device with the tap as a sub-tap and the display as the main sub-device, and an IOProc that scales the tap input into the device output. The volume keys are captured with a session-level CGEvent tap. Source (three files, Swift and Objective-C): https://github.com/mevlut-geredeli/MonitorKeys Observations that may be useful to others using taps: The tap delivers IOProc callbacks only while some process is rendering; at idle there are no
Replies
0
Boosts
0
Views
272
Activity
1w