Search results for

“sandbox”

10,542 results found

Post

Replies

Boosts

Views

Activity

Reply to request for a kernel I/O passthrough API for file-backed volumes (FUSE_PASSTHROUGH / ProjFS equivalent)
Thanks Kevin, that's fair for a stable hierarchy, but it doesn't really hold for this workload. The clone/disk-image approach assumes the input set is something you provision once and then snapshot per action. Bazel's isn't. The files I project live in output_base (external repo cache, bazel-out, action outputs), which is rewritten constantly across and within builds — so there's nothing stable to clone, and an image you have to unmount to clone cheaply is a non-starter when it's written on basically every action. The inputs are also spread across multiple volumes, and clonefile is same-volume only, so the cross-volume case can't clone at all — you'd have to first copy everything into one place, which reintroduces the per-action materialization cost (over a moving target) that passthrough is meant to avoid. On EndpointSecurity — interesting pattern, and I see the appeal over sandbox-exec, but it's the same model: observe an access and allow/deny it. Bazel's sandbox is already built on sandbox
Topic: App & System Services SubTopic: Core OS Tags:
Jun ’26
Reply to request for a kernel I/O passthrough API for file-backed volumes (FUSE_PASSTHROUGH / ProjFS equivalent)
I sent the feedback request a while back; it’s FB22596726 I took a look at the bug, and there's one small comment I wanted to add. Inside the bug, there's a comment about how the sandbox is slow and leaky because it's built on symlinks into the original hierarchy. Basically, I don't know why anyone would choose to use symlinks for this when APFS and file cloning are available. The way I would actually implement this is: Copy/clone the entire hierarchy into a private location, so you're now working on an isolated copy. Generate the sandbox for individual operations using clones of the object from #1. Note that this basic approach has many variations and alternatives. For example: Moving to a private location means that you are no longer in the public (meaning, the area users see and interact with) file system, which means using directory (not just file cloning) is now an option. I have a whole write-up on this here, but the performance difference between directory and file cloning can be quit
Topic: App & System Services SubTopic: Core OS Tags:
Jun ’26
Subscriptions fail to load during App Review but work correctly in TestFlight
To the Apple Review and Developer Support Teams, We are experiencing the same issue described in this thread: https://developer.apple.com/forums/thread/827016 Our application has been rejected under Guideline 2.1 - Performance because the subscription plans do not load during the App Review process. According to the review feedback, there's an error indicating that the In-App Purchases product list is empty. We are unable to reproduce this issue on our side. The subscription screen works correctly in TestFlight on multiple physical devices and with sandbox tester accounts. The paywall loads successfully, localized prices are returned correctly, and test purchases can be completed without errors. We have verified the following: All subscription products are attached to the submitted app version in App Store Connect. The product identifiers used in the application match the identifiers configured in App Store Connect. The relevant agreements, tax information, and banking details are active and up to da
4
0
1.2k
Jun ’26
Title: PackageKit install fails with PKInstallErrorDomain Code=120 and NSPOSIXErrorDomain Code=1 during _relinkFile operation Body: We are investigating an intermittent package installation failure on macOS Tahoe 26.5 and are trying to understand
We are investigating an intermittent package installation failure on macOS Tahoe 26.5 and are trying to understand the conditions under which PackageKit may return the following errors during an upgrade installation: PKInstallErrorDomain Code=120 NSPOSIXErrorDomain Code=1 (Operation not permitted) The package successfully passes validation and authorization, and pre-install scripts complete successfully. The failure occurs during the final PackageKit commit phase when PackageKit attempts to move/relink content from the installer sandbox to the destination volume. Relevant log snippets: PackageKit: Shoving /Root to / Error relinking file (primary): .../Contents/_CodeSignature/CodeResources failed _relinkFile(...) Operation not permitted PackageKit: Install Failed: Error Domain=PKInstallErrorDomain Code=120 NSUnderlyingError: Error Domain=NSPOSIXErrorDomain Code=1 Operation not permitted The issue is intermittent and only affects a subset of systems. The same package installs successfully on many machi
6
0
599
Jun ’26
889 CoreData errors in a SwiftData app of less than 30 lines
I have created a SwiftData iOS app from Paul Hudson's Hacking With Swift series in order to troubleshoot some SwiftData issues I am having in a separate app. I have raised > FB22925785 I have gone back to basics to try and problem solve so I have used the first part of an app of Paul's from [https://www.hackingwithswift.com/quick-start/swiftdata/defining-a-data-model-with-swiftdata] The App is very simple and only contains the following import SwiftData import SwiftUI @main struct iTour_from_scratchApp: App { var body: some Scene { WindowGroup { ContentView() .modelContainer(for: Destination.self) } } } The data is import SwiftData @Model class Destination { var name: String var details: String var date: Date var priority: Int init(name: String, details: String, date: Date, priority: Int) { self.name = name self.details = details self.date = date self.priority = priority } } The view is import SwiftUI struct ContentView: View { var body: some View { VStack { Image(systemName: globe) .imageScale(.large) .fo
1
0
738
Jun ’26
Reply to StoreKit 2 Product.displayPrice returns USD while purchase dialog shows EUR
Hello - StoreKit is expected to return a product's configured price and currency in line with the Storefront setting in place for your testing scenario. You can use the Storefront API to determine the current storefront at any time, in any testing scenario. Depending on the specifics of your testing setup, you may need to make configuration adjustments to ensure you are testing in the desired storefront. If you are using StoreKit Testing Xcode, ensure that your StoreKit configuration file has the correct default Storefront value set. For Sandbox testing, you can set and modify the storefront for each Sandbox tester account you create. When testing in TestFlight, you may need to log out of a device's production account and then log in as a Sandbox user to force the desired storefront. It may also be helpful to review these Technotes for more information about testing in Xcode and Sandbox. Please let us know if you need any additional assistance. Thank you.
Topic: App & System Services SubTopic: StoreKit Tags:
Jun ’26
Reply to request for a kernel I/O passthrough API for file-backed volumes (FUSE_PASSTHROUGH / ProjFS equivalent)
This also will help with executable binary performance on these mounts where AMFI wants to read the executables and verify their signatures, such api will probably allow AMFI to see that these vnodes are basically aliases and hopefully skip the validation? On workloads such as Bazel, AMFI serializes the sandboxed actions.
Topic: App & System Services SubTopic: Core OS Tags:
Jun ’26
Reply to StoreKit 2 currentEntitlements persists after Sandbox Purchase History reset in TestFlight
Yes, I tried signing out and back in after clearing purchase history, but it did not help. The entitlement is still returned by Transaction.currentEntitlements for the original Product ID. Reinstalling, rebooting, and configuring a Sandbox Apple Account did not clear it either. Changing the Product ID makes the entitlement disappear, so it looks tied to the original TestFlight/Apple ID receipt. Is there any supported way to reset this for a non-consumable TestFlight purchase?
Topic: App & System Services SubTopic: StoreKit Tags:
Jun ’26
IAP rejected under 2.1(b) "failed to load" — products work in Sandbox/TestFlight but fail in App Review
I'm getting repeatedly rejected under Guideline 2.1(b) - App Completeness, with the message that the in-app purchase products failed to load. This has happened on multiple submissions now, and I'm stuck because everything works fine on my end. My setup: 2 auto-renewable subscriptions + 1 in-app purchase, all in Waiting for Review status and attached to the current version (1.0.0). All three products load and purchase successfully when I test via TestFlight with a Sandbox account. No errors at all. Paid Apps Agreement, banking, and tax forms are all Active. I have another app on the same account where IAPs are live and working, so I don't think it's an account/agreement issue. Review device was iPad Air 11-inch (M3), iPadOS 26.5. One detail that might be relevant: this account was migrated from an individual to an organization account a while back, and there were some app transfers involved on the account (though not for this specific app). What I've already tried/confirmed: Product IDs in code match
0
0
331
Jun ’26
request for a kernel I/O passthrough API for file-backed volumes (FUSE_PASSTHROUGH / ProjFS equivalent)
What I'm building An FSUnaryFileSystem that projects a large, read-mostly tree of existing on-disk files into a sandbox namespace — a build sandbox that lays out an action's declared inputs and points outputs at host scratch. This is squarely the replace a third-party kext (macFUSE-style) with FSKit use case, and it's a projection/overlay filesystem: nearly every file the volume serves is just a view of a regular file that already exists on a local APFS volume. The problem For file content, the only available path for a file-backed (non-block-device) volume is FSVolumeReadWriteOperations — every read that misses UBC is an XPC round-trip into my extension, where I memcpy from the backing file into the kernel buffer. The kernel already has, or could trivially open, the backing file; instead each page-in becomes: pagein → IPC → extension read → copy → return. FSVolumeKernelOffloadedIOOperations looks like the intended fast path, but it's built around FSBlockDeviceResource — i.e. it assumes the
6
0
285
Jun ’26
In-App Purchase Resources
General: Forums topic: StoreKit Forums tag: In-App Purchase App Store Pathway Simple and safe In-App Purchases Auto-renewable subscriptions In-App Purchase documentation Getting started with In-App Purchase using StoreKit views documentation Supporting business model changes by using the app transaction documentation Testing at all stages of development with Xcode and the sandbox documentation App Store Server Notifications documentation App Store Server API documentation Simplifying your implementation by using the App Store Server Library documentation TN3185: Troubleshooting In-App Purchases availability in Xcode technote TN3186: Troubleshooting In-App Purchases availability in the sandbox technote TN3188: Troubleshooting In-App Purchases availability in the App Store technote Understanding StoreKit workflows sample code Implementing a store in your app using the StoreKit API sample code What’s new in StoreKit and In-App Purchase video
0
0
1.9k
Jun ’26
Reply to OpenZFS on FSKit — Proof of Concept
Part 2: ARC memory limits. ZFS's Adaptive Replacement Cache is designed to use a significant portion of system RAM. Sandbox memory limits constrain it. A declared buffer cache process role with higher memory entitlements would meaningfully improve performance. I confess, I haven't actually looked into this. What's the limit you’re actually hitting and how much memory do you think/need/want? Also, what API are you reading with and have you tried using metadataRead(into:startingAt:length:)? I'm not sure if it will help or not (it depends on what limit you’re actually hitting), but part of the reason there are two APIs is that the metadata APIs change how memory ownership (the kernel vs. your process) is accounted for, which can reduce your processes’ perceived footprint. Background operations. Pool scrub and vdev resilver (RAID rebuild) are long-running background I/O tasks essential for data integrity. There's no mechanism for an FSKit extension to run sustained background work while mounted. I'm not
Topic: App & System Services SubTopic: Core OS Tags:
Jun ’26
Reply to OpenZFS on FSKit — Proof of Concept
Part 1: Technical Findings — Things That Weren't Obvious First off, thank you for all your comments! I'm a bit buried preparing for WWDC, but I do have some comments to pass along: startCheckWithTask: must complete asynchronously This is actually fairly common in our frameworks, but probably worth documenting better. app-sandbox=true is required in entitlements ExtensionKit rejects the extension entirely without com.apple.security.app-sandbox=true, even though sandboxing a filesystem extension feels counterintuitive. This needs to be paired with com.apple.developer.fskit.fsmodule=true. This isn't so much saying I'm sandboxed as it's saying I acknowledge that I will be executing inside a sandbox. ALL ExtensionKit extensions ARE sandboxed because part of what the extension points execution environment defines... is the sandbox environment that extension will run in. I think part of the confusion here is that we commonly use the term sandboxed
Topic: App & System Services SubTopic: Core OS Tags:
Jun ’26
Reply to Mac Catalyst App No longer start : Cause bugs in App Store and weird macOS behaviour
[quote='889533022, ShaddamIV, /thread/828110?answerId=889533022#889533022, /profile/ShaddamIV'] But I will check from the terminal to see if I can get more infos. [/quote] Cool. I look forward to the results. [quote='889533022, ShaddamIV, /thread/828110?answerId=889533022#889533022, /profile/ShaddamIV'] macOS should have a way to uninstall an app for real [/quote] As I mentioned above, this is technically challenging, but if you’d like request this officially I recommend that you file it in Feedback Assistant. Please post your bug number, just for the record. [quote='889533022, ShaddamIV, /thread/828110?answerId=889533022#889533022, /profile/ShaddamIV'] macCatalyst app are sandboxed [/quote] Just to be clear, Mac Catalyst apps don’t have to be sandboxed. Rather, the Mac App Store requires sandboxing. And macOS gives you the option to distribute directly using Developer ID signing. However, I can understand why folks choose to ship their app on the Mac App Store, so your point is wel
Topic: App & System Services SubTopic: General Tags:
Jun ’26
Reply to APNs token auth suddenly returns InvalidProviderToken for active team-scoped APNs key
Thank you so much for your time!! — I tested both tools in the Push Notifications Console. Selected app/context: App/topic: app.terrasignal Console URL context appears to be: teams/837F2XGDX/app/app.terrasignal Device Token Validator: Result: Valid Message shown: “Device Token is valid for sending Alert & Background push-type notifications in the Development environment.” This was the current sandbox/development token generated by the app and registered with my server. JSON Web Token Validator: Result: Failed Error shown: “Team Id in request does not match with Issuer (iss) in token” The JWT was generated on my VPS using the active APNs key HNW7XPK2H3 and Team ID 837F2XGDX. JWT header: { alg: ES256, kid: HNW7XPK2H3 } JWT payload: { iss: 837F2XGDX, iat: 1780268873 } I did not post the full JWT or private key publicly. This seems to narrow the issue: The device token validates successfully for Development. The app/topic selected in Push Notifications Console is app.terrasignal. The visible console
May ’26
Reply to request for a kernel I/O passthrough API for file-backed volumes (FUSE_PASSTHROUGH / ProjFS equivalent)
Thanks Kevin, that's fair for a stable hierarchy, but it doesn't really hold for this workload. The clone/disk-image approach assumes the input set is something you provision once and then snapshot per action. Bazel's isn't. The files I project live in output_base (external repo cache, bazel-out, action outputs), which is rewritten constantly across and within builds — so there's nothing stable to clone, and an image you have to unmount to clone cheaply is a non-starter when it's written on basically every action. The inputs are also spread across multiple volumes, and clonefile is same-volume only, so the cross-volume case can't clone at all — you'd have to first copy everything into one place, which reintroduces the per-action materialization cost (over a moving target) that passthrough is meant to avoid. On EndpointSecurity — interesting pattern, and I see the appeal over sandbox-exec, but it's the same model: observe an access and allow/deny it. Bazel's sandbox is already built on sandbox
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jun ’26
Reply to request for a kernel I/O passthrough API for file-backed volumes (FUSE_PASSTHROUGH / ProjFS equivalent)
I sent the feedback request a while back; it’s FB22596726 I took a look at the bug, and there's one small comment I wanted to add. Inside the bug, there's a comment about how the sandbox is slow and leaky because it's built on symlinks into the original hierarchy. Basically, I don't know why anyone would choose to use symlinks for this when APFS and file cloning are available. The way I would actually implement this is: Copy/clone the entire hierarchy into a private location, so you're now working on an isolated copy. Generate the sandbox for individual operations using clones of the object from #1. Note that this basic approach has many variations and alternatives. For example: Moving to a private location means that you are no longer in the public (meaning, the area users see and interact with) file system, which means using directory (not just file cloning) is now an option. I have a whole write-up on this here, but the performance difference between directory and file cloning can be quit
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jun ’26
Subscriptions fail to load during App Review but work correctly in TestFlight
To the Apple Review and Developer Support Teams, We are experiencing the same issue described in this thread: https://developer.apple.com/forums/thread/827016 Our application has been rejected under Guideline 2.1 - Performance because the subscription plans do not load during the App Review process. According to the review feedback, there's an error indicating that the In-App Purchases product list is empty. We are unable to reproduce this issue on our side. The subscription screen works correctly in TestFlight on multiple physical devices and with sandbox tester accounts. The paywall loads successfully, localized prices are returned correctly, and test purchases can be completed without errors. We have verified the following: All subscription products are attached to the submitted app version in App Store Connect. The product identifiers used in the application match the identifiers configured in App Store Connect. The relevant agreements, tax information, and banking details are active and up to da
Replies
4
Boosts
0
Views
1.2k
Activity
Jun ’26
Title: PackageKit install fails with PKInstallErrorDomain Code=120 and NSPOSIXErrorDomain Code=1 during _relinkFile operation Body: We are investigating an intermittent package installation failure on macOS Tahoe 26.5 and are trying to understand
We are investigating an intermittent package installation failure on macOS Tahoe 26.5 and are trying to understand the conditions under which PackageKit may return the following errors during an upgrade installation: PKInstallErrorDomain Code=120 NSPOSIXErrorDomain Code=1 (Operation not permitted) The package successfully passes validation and authorization, and pre-install scripts complete successfully. The failure occurs during the final PackageKit commit phase when PackageKit attempts to move/relink content from the installer sandbox to the destination volume. Relevant log snippets: PackageKit: Shoving /Root to / Error relinking file (primary): .../Contents/_CodeSignature/CodeResources failed _relinkFile(...) Operation not permitted PackageKit: Install Failed: Error Domain=PKInstallErrorDomain Code=120 NSUnderlyingError: Error Domain=NSPOSIXErrorDomain Code=1 Operation not permitted The issue is intermittent and only affects a subset of systems. The same package installs successfully on many machi
Replies
6
Boosts
0
Views
599
Activity
Jun ’26
889 CoreData errors in a SwiftData app of less than 30 lines
I have created a SwiftData iOS app from Paul Hudson's Hacking With Swift series in order to troubleshoot some SwiftData issues I am having in a separate app. I have raised > FB22925785 I have gone back to basics to try and problem solve so I have used the first part of an app of Paul's from [https://www.hackingwithswift.com/quick-start/swiftdata/defining-a-data-model-with-swiftdata] The App is very simple and only contains the following import SwiftData import SwiftUI @main struct iTour_from_scratchApp: App { var body: some Scene { WindowGroup { ContentView() .modelContainer(for: Destination.self) } } } The data is import SwiftData @Model class Destination { var name: String var details: String var date: Date var priority: Int init(name: String, details: String, date: Date, priority: Int) { self.name = name self.details = details self.date = date self.priority = priority } } The view is import SwiftUI struct ContentView: View { var body: some View { VStack { Image(systemName: globe) .imageScale(.large) .fo
Replies
1
Boosts
0
Views
738
Activity
Jun ’26
Reply to StoreKit 2 Product.displayPrice returns USD while purchase dialog shows EUR
Hello - StoreKit is expected to return a product's configured price and currency in line with the Storefront setting in place for your testing scenario. You can use the Storefront API to determine the current storefront at any time, in any testing scenario. Depending on the specifics of your testing setup, you may need to make configuration adjustments to ensure you are testing in the desired storefront. If you are using StoreKit Testing Xcode, ensure that your StoreKit configuration file has the correct default Storefront value set. For Sandbox testing, you can set and modify the storefront for each Sandbox tester account you create. When testing in TestFlight, you may need to log out of a device's production account and then log in as a Sandbox user to force the desired storefront. It may also be helpful to review these Technotes for more information about testing in Xcode and Sandbox. Please let us know if you need any additional assistance. Thank you.
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Jun ’26
Reply to request for a kernel I/O passthrough API for file-backed volumes (FUSE_PASSTHROUGH / ProjFS equivalent)
This also will help with executable binary performance on these mounts where AMFI wants to read the executables and verify their signatures, such api will probably allow AMFI to see that these vnodes are basically aliases and hopefully skip the validation? On workloads such as Bazel, AMFI serializes the sandboxed actions.
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jun ’26
Reply to StoreKit 2 currentEntitlements persists after Sandbox Purchase History reset in TestFlight
Yes, I tried signing out and back in after clearing purchase history, but it did not help. The entitlement is still returned by Transaction.currentEntitlements for the original Product ID. Reinstalling, rebooting, and configuring a Sandbox Apple Account did not clear it either. Changing the Product ID makes the entitlement disappear, so it looks tied to the original TestFlight/Apple ID receipt. Is there any supported way to reset this for a non-consumable TestFlight purchase?
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Jun ’26
IAP rejected under 2.1(b) "failed to load" — products work in Sandbox/TestFlight but fail in App Review
I'm getting repeatedly rejected under Guideline 2.1(b) - App Completeness, with the message that the in-app purchase products failed to load. This has happened on multiple submissions now, and I'm stuck because everything works fine on my end. My setup: 2 auto-renewable subscriptions + 1 in-app purchase, all in Waiting for Review status and attached to the current version (1.0.0). All three products load and purchase successfully when I test via TestFlight with a Sandbox account. No errors at all. Paid Apps Agreement, banking, and tax forms are all Active. I have another app on the same account where IAPs are live and working, so I don't think it's an account/agreement issue. Review device was iPad Air 11-inch (M3), iPadOS 26.5. One detail that might be relevant: this account was migrated from an individual to an organization account a while back, and there were some app transfers involved on the account (though not for this specific app). What I've already tried/confirmed: Product IDs in code match
Replies
0
Boosts
0
Views
331
Activity
Jun ’26
request for a kernel I/O passthrough API for file-backed volumes (FUSE_PASSTHROUGH / ProjFS equivalent)
What I'm building An FSUnaryFileSystem that projects a large, read-mostly tree of existing on-disk files into a sandbox namespace — a build sandbox that lays out an action's declared inputs and points outputs at host scratch. This is squarely the replace a third-party kext (macFUSE-style) with FSKit use case, and it's a projection/overlay filesystem: nearly every file the volume serves is just a view of a regular file that already exists on a local APFS volume. The problem For file content, the only available path for a file-backed (non-block-device) volume is FSVolumeReadWriteOperations — every read that misses UBC is an XPC round-trip into my extension, where I memcpy from the backing file into the kernel buffer. The kernel already has, or could trivially open, the backing file; instead each page-in becomes: pagein → IPC → extension read → copy → return. FSVolumeKernelOffloadedIOOperations looks like the intended fast path, but it's built around FSBlockDeviceResource — i.e. it assumes the
Replies
6
Boosts
0
Views
285
Activity
Jun ’26
In-App Purchase Resources
General: Forums topic: StoreKit Forums tag: In-App Purchase App Store Pathway Simple and safe In-App Purchases Auto-renewable subscriptions In-App Purchase documentation Getting started with In-App Purchase using StoreKit views documentation Supporting business model changes by using the app transaction documentation Testing at all stages of development with Xcode and the sandbox documentation App Store Server Notifications documentation App Store Server API documentation Simplifying your implementation by using the App Store Server Library documentation TN3185: Troubleshooting In-App Purchases availability in Xcode technote TN3186: Troubleshooting In-App Purchases availability in the sandbox technote TN3188: Troubleshooting In-App Purchases availability in the App Store technote Understanding StoreKit workflows sample code Implementing a store in your app using the StoreKit API sample code What’s new in StoreKit and In-App Purchase video
Replies
0
Boosts
0
Views
1.9k
Activity
Jun ’26
Reply to OpenZFS on FSKit — Proof of Concept
Part 2: ARC memory limits. ZFS's Adaptive Replacement Cache is designed to use a significant portion of system RAM. Sandbox memory limits constrain it. A declared buffer cache process role with higher memory entitlements would meaningfully improve performance. I confess, I haven't actually looked into this. What's the limit you’re actually hitting and how much memory do you think/need/want? Also, what API are you reading with and have you tried using metadataRead(into:startingAt:length:)? I'm not sure if it will help or not (it depends on what limit you’re actually hitting), but part of the reason there are two APIs is that the metadata APIs change how memory ownership (the kernel vs. your process) is accounted for, which can reduce your processes’ perceived footprint. Background operations. Pool scrub and vdev resilver (RAID rebuild) are long-running background I/O tasks essential for data integrity. There's no mechanism for an FSKit extension to run sustained background work while mounted. I'm not
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jun ’26
Reply to OpenZFS on FSKit — Proof of Concept
Part 1: Technical Findings — Things That Weren't Obvious First off, thank you for all your comments! I'm a bit buried preparing for WWDC, but I do have some comments to pass along: startCheckWithTask: must complete asynchronously This is actually fairly common in our frameworks, but probably worth documenting better. app-sandbox=true is required in entitlements ExtensionKit rejects the extension entirely without com.apple.security.app-sandbox=true, even though sandboxing a filesystem extension feels counterintuitive. This needs to be paired with com.apple.developer.fskit.fsmodule=true. This isn't so much saying I'm sandboxed as it's saying I acknowledge that I will be executing inside a sandbox. ALL ExtensionKit extensions ARE sandboxed because part of what the extension points execution environment defines... is the sandbox environment that extension will run in. I think part of the confusion here is that we commonly use the term sandboxed
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Jun ’26
Reply to Mac Catalyst App No longer start : Cause bugs in App Store and weird macOS behaviour
[quote='889533022, ShaddamIV, /thread/828110?answerId=889533022#889533022, /profile/ShaddamIV'] But I will check from the terminal to see if I can get more infos. [/quote] Cool. I look forward to the results. [quote='889533022, ShaddamIV, /thread/828110?answerId=889533022#889533022, /profile/ShaddamIV'] macOS should have a way to uninstall an app for real [/quote] As I mentioned above, this is technically challenging, but if you’d like request this officially I recommend that you file it in Feedback Assistant. Please post your bug number, just for the record. [quote='889533022, ShaddamIV, /thread/828110?answerId=889533022#889533022, /profile/ShaddamIV'] macCatalyst app are sandboxed [/quote] Just to be clear, Mac Catalyst apps don’t have to be sandboxed. Rather, the Mac App Store requires sandboxing. And macOS gives you the option to distribute directly using Developer ID signing. However, I can understand why folks choose to ship their app on the Mac App Store, so your point is wel
Topic: App & System Services SubTopic: General Tags:
Replies
Boosts
Views
Activity
Jun ’26
Reply to APNs token auth suddenly returns InvalidProviderToken for active team-scoped APNs key
Thank you so much for your time!! — I tested both tools in the Push Notifications Console. Selected app/context: App/topic: app.terrasignal Console URL context appears to be: teams/837F2XGDX/app/app.terrasignal Device Token Validator: Result: Valid Message shown: “Device Token is valid for sending Alert & Background push-type notifications in the Development environment.” This was the current sandbox/development token generated by the app and registered with my server. JSON Web Token Validator: Result: Failed Error shown: “Team Id in request does not match with Issuer (iss) in token” The JWT was generated on my VPS using the active APNs key HNW7XPK2H3 and Team ID 837F2XGDX. JWT header: { alg: ES256, kid: HNW7XPK2H3 } JWT payload: { iss: 837F2XGDX, iat: 1780268873 } I did not post the full JWT or private key publicly. This seems to narrow the issue: The device token validates successfully for Development. The app/topic selected in Push Notifications Console is app.terrasignal. The visible console
Replies
Boosts
Views
Activity
May ’26