Search results for

“sandbox”

10,542 results found

Post

Replies

Boosts

Views

Activity

Reply to Can't verify my identity for sandbox can not receive verification code
Update: I was at 10 devices. I signed out of one, but nothing at all changed. I signed out of 2 more, and now my primary mobile number, when used to confirm a sandbox account, does NOT say: Could not connect to iCloud - This phone number has been used too many times. Choose a different number. ...now it says... Too Many Codes Sent - You have sent too many codes to this phone number. Please enter the last code you received, enter another phone number or try again later. (Of course I never received any codes at all. From either number.) It is then waiting for me to enter a code. (Regardless of which number I try.) I have no codes for either. I'll try again tomorrow.
May ’26
Can't verify my identity for sandbox can not receive verification code
I'm trying to use a sandbox account, and am stuck on the verification stage. My primary number (my personal iPhone phone number) has been used too many time, as I've used it to set up many devices. My personal mobile number is tied to a physical SIM in my iPhone 12 Pro. Now I'm trying to use a Freedom Mobile eSIM, and can successfully send and received texts to/from myself, other people, to/from Freedom Mobile as well. Setting up the sandbox account (my email address with a +3 at the end of it) I choose USE A DIFFERENT NUMBER and my eSIM number is shown along with my Freedom description of the eSIM right below it. The Verification Code page appears, but I never get a verification code. I click on DID NOT GET A VERIFICATION CODE? and try trigger a phone call and do not get that either. I've reset my eSIM, I've reset my iPhone's networking, I've rebooted my phone many times, I've un/re-installed the app and TestFlight. I'm willing to try anything here, but is it possible because my personal mo
3
0
481
May ’26
Reply to StoreKit 2 returns empty products array on device (iPhone) even though IAP is Ready to Submit
Hello - In reviewing your account, it appears that the required Paid Apps Agreement has not been signed and is not yet in the Active state. Because of this, your In-App Purchase products are not available for testing in Sandbox or for purchase in Production. Please direct the Account Holder to accept the Paid Apps Agreement, complete both the Banking and Tax information, and ensure the status of this agreement is updated to ACTIVE. We also recommend completing a successful Sandbox purchase in your app. Please let us know if you have any additional questions or need further assistance. Thank you.
May ’26
First subscription stuck in "Developer Action Needed", no IAP section on version page, reviewer hits "product is not available for purchase" — works fine on my own TestFlight install
I'm preparing my first App Store submission and have hit a chain of issues that appear to be backend state problems I can't resolve from the App Store Connect UI. I've already opened a DTS case but wanted to ask here in case anyone has seen this combination before. Setup: iOS app with first-time subscriptions (auto-renewable, 7-day free trial) Two products: bitcoinhq_pro_monthly and bitcoinhq_pro_annual Both in the same subscription group Bitcoin HQ Pro Paid Apps Agreement is Active Bundle ID, prices (all 175 territories including United States), intro offers (Free for the first week in all territories), localizations all configured Important context: On my own iPad (TestFlight build, signed into my normal sandbox account), the full flow works perfectly — paywall loads on first launch after install, both products show with correct prices, tapping Subscribe opens the StoreKit sheet, purchase completes, the entitlement grants, and Pro features unlock. So the app code and RevenueCat configuration are wo
0
0
398
May ’26
Reply to How much practical benefit is there to XPC-based privilege separation?
There are a couple of ways XPC services can help with security. The first is the one you’re talking about, that is, where you give the XPC service elevated privileges. Your ‘delete a user’ example isn’t great though, because deleting arbitrary users is problematic and it also requires BSD privileged escalation. So let’s consider a different example. Consider a sandboxed app that wants to install an item in ~/Library/PDF Services. There are no BSD level blocks to doing that, but it is blocked by the App Sandbox. To get around that block you sign the app with the com.apple.security.temporary-exception.files.home-relative-path.read-write temporary exception entitlement. Cool, problem solved! Note For links to more about temporary exception entitlements, and the App Sandbox in general, see App Sandbox Resources. However, if your app gets compromised then it might install arbitrary stuff into ~/Library/PDF Services, which isn’t great. So instead you move that code into an XPC se
Topic: Privacy & Security SubTopic: General Tags:
May ’26
Reply to How much practical benefit is there to XPC-based privilege separation?
I was about to respond in a similar fashion. An exploit is typically considered a binary operation. The app is either secure or exploited. XPC Services make that a floating point. The app can be partially exploited, on either the main or the XPC side(s). That both limits the risk and increases the cost of the exploit. However, then you mentioned daemons. That's something completely different. XPC is many different things. It is a communication protocol that can be used by both XPC services and daemons. But XPC services are not the same thing as daemons. XPC services are easy to use and deploy. They give you some flexibility with sandboxing. But there's nothing easy about daemons, including The XPC communication.
Topic: Privacy & Security SubTopic: General Tags:
May ’26
How much practical benefit is there to XPC-based privilege separation?
Privilege separation is one of the two main reasons to use XPC services given by https://developer.apple.com/library/archive/documentation/MacOSX/Conceptual/BPSystemStartup/Chapters/CreatingXPCServices.html — With traditional applications, if an application becomes compromised through a buffer overflow or other security vulnerability, the attacker gains the ability to do anything that the user can do. To mitigate this risk, Mac OS X provides sandboxing—limiting what types of operations a process can perform. […] Each XPC service has its own sandbox, so XPC services can make it easier to implement proper privilege separation. The idea (iiuc) being that if the main process is compromised, the spicier operations have been separated out to a separate process space, and this improves the security of the system. But if the main process is compromised, and that main process is trusted by the more-privileged XPC service, is not the system still compromised in practice? That is rather than the exploi
3
0
500
May ’26
App Subscription "Confirm with Apple Device" UI
My tvOS app includes the purchase of subscriptions, and I am updating the code with Storekit 2.0. I have seen other apps that present the Confirm with Apple Device UI upon selection of a product, but for me I only ever see an alert confirming the purchase. I have tested this using Xcode storekit data and a sandbox account. I have also attempted using Storekit views and passing the UIWindowScene to the purchase(confirmIn: ) parameter, but neither made any difference. Is there some limitation that prevents that UI from showing in debug builds?
1
0
793
May ’26
Reply to StoreKit 2: Transaction.all and Transaction.currentEntitlements return empty for valid non-consumable purchases in production
We’ve now conducted additional tests. We have a 10-year-old app with around 800 downloads per day that has already been migrated to StoreKit 2 for quite some time. With real users in the live app, there are no issues — purchases can be made and restored successfully. However, with a sandbox test user while launching the app from Xcode, neither purchasing nor restoring works. In another 13-year-old app with around 1,800 downloads per day, StoreKit 2 works perfectly both live and with the sandbox test user without any issues. All apps use the exact same code for the StoreKit 2 logic and are tested with the same users. Today we will take the risk and submit the app we were originally talking about for review after switching to StoreKit 2, and test whether it works live without any problems.
Topic: App & System Services SubTopic: StoreKit Tags:
May ’26
Sectigo Public Server Authentication CA DV R36?
When I submit an https web request I receive both of those funny errors. In particular I do not understand what that “Sectigo Public Server Authentication” message represents, perhaps yet another certification for Apple to access the request, when of course by connecting to that web address on Safari produces no errors. Connection error: Error Domain=NSCocoaErrorDomain Code=4099 The connection to service named com.apple.PerfPowerTelemetryClientRegistrationService was invalidated: Connection init failed at lookup with error 159 - Sandbox restriction. UserInfo={NSDebugDescription=The connection to service named com.apple.PerfPowerTelemetryClientRegistrationService was invalidated: Connection init failed at lookup with error 159 - Sandbox restriction.} (+[PPSClientDonation isRegisteredSubsystem:category:]) Permission denied: Maps / SpringfieldUsage (+[PPSClientDonation sendEventWithIdentifier:payload:]) Invalid inputs: payload={ isSPR = 1; } urlstring=https://taxiprofessional.net/***.php proces
1
0
360
May ’26
App Store Server Notification v2: how to distinguish a resubscription that happened in-app from one that happened in Settings → Subscriptions?
Context We're handling App Store subscriptions on the server side using App Store Server Notification v2. Our pipeline currently identifies each event by transactionId and originalTransactionId. A few notes about our client: Our app is built with Flutter and uses the standard in_app_purchase plugin layer to drive App Store purchases (StoreKit 1 under the hood). We have not migrated to StoreKit 2 on the client yet. We have not been setting SKPayment.applicationUsername on outgoing purchases, so every transaction we've ever produced has appAccountToken: null in its v2 notification. This question is purely about what the server-side notification can tell us, given the current client state above. What we're trying to figure out A user can resubscribe to an expired subscription in two different places: In-app — the user opens our app and re-purchases through our normal in-app purchase flow. App Store — the user goes to Settings → Apple ID → Subscriptions and resubscribes from the system UI, without ever returning
1
0
1.2k
May ’26
Reply to IOServiceOpen returns kIOReturnError (0xE00002BC) before NewUserClient — DEXT matches and opens pipes successfully
Any pointer to the correct invocation (or a Configuration Profile to enable DriverKit verbose logging) would unblock me. Two points here: I have a post here about IOLog's oddness which is worth reviewing. That post also has the macro that's supposed to log publicly, so you can confirm your logging is doing what it's supposed to do. There was one developer post about DriverKit logging weirdness, which we never heard back on. IF you determine that this is some kind of system bug, then I'd appreciate you filing a bug on this. Quinn's Your Friend the System Log and Recording Private Data in the System Log both cover how you can manage logging redaction in more detail. One detail that alluded to there is that the SystemLogging.System payload lets you disable ALL private data redaction system wide. Expanding on that last point, while I wouldn't leave redaction disabled, particularly on any machine your actually using, that does provide a quick and easy way to see exactly what data was being logged. That can make it
Topic: App & System Services SubTopic: Drivers Tags:
May ’26
Reply to StoreKit 2: Transaction.all and Transaction.currentEntitlements return empty for valid non-consumable purchases in production
We have been experiencing the same issue for a few days now in two of our apps. Users have reported it via email and through negative App Store reviews. In all of our other apps, in-app purchases are still working without any problems. In our case, the issue affects non-consumable in-app purchases (one-time purchases). In one of the affected apps, we can reproduce the issue with a Sandbox user. The problem occurs not only with StoreKit 2, but also with the old StoreKit implementation. We noticed it because we are currently migrating this app to StoreKit 2. With StoreKit 1, in-app purchases can be restored using restoreCompletedTransactions. But when trying to purchase an in-app purchase that has already been bought, the App Store displays a message saying that the item has already been purchased and asks whether it should be downloaded again for free. However, the download/restore then fails: Printing description of nsError: Error Domain=SKErrorDomain Code=0 Ein unbekannter Fehler ist aufgetreten Use
Topic: App & System Services SubTopic: StoreKit Tags:
May ’26
"Unable to Manage Sandbox Test Account - Popup Closes on 'Manage' Click"
Issue: Sandbox test account stuck in a loop when trying to access account management Environment: iOS version: [iOS 26.4.2] Device: iPhone 12 Steps to Reproduce: Created sandbox test credentials on Apple Developer site (App Store Connect → Users and Access → Sandbox → Testers) On iPhone, navigated to Settings → Developer → Sandbox Apple Account Clicked Sign In and entered sandbox test email and password Successfully verified using verification codes (both email and phone number) Clicked on the signed-in sandbox account A popup appears with Manage option Clicked Manage Expected Behavior:- Should open sandbox account management interface Actual Behavior:- Popup immediately closes and the same popup reappears. Clicking Manage again produces the same result - an endless loop preventing access to account management. Has anyone encountered this issue with sandbox test accounts? Is there a known workaround or fix for this behavior?
2
0
535
May ’26
Reply to Can't verify my identity for sandbox can not receive verification code
Update: I was at 10 devices. I signed out of one, but nothing at all changed. I signed out of 2 more, and now my primary mobile number, when used to confirm a sandbox account, does NOT say: Could not connect to iCloud - This phone number has been used too many times. Choose a different number. ...now it says... Too Many Codes Sent - You have sent too many codes to this phone number. Please enter the last code you received, enter another phone number or try again later. (Of course I never received any codes at all. From either number.) It is then waiting for me to enter a code. (Regardless of which number I try.) I have no codes for either. I'll try again tomorrow.
Replies
Boosts
Views
Activity
May ’26
Can't verify my identity for sandbox can not receive verification code
I'm trying to use a sandbox account, and am stuck on the verification stage. My primary number (my personal iPhone phone number) has been used too many time, as I've used it to set up many devices. My personal mobile number is tied to a physical SIM in my iPhone 12 Pro. Now I'm trying to use a Freedom Mobile eSIM, and can successfully send and received texts to/from myself, other people, to/from Freedom Mobile as well. Setting up the sandbox account (my email address with a +3 at the end of it) I choose USE A DIFFERENT NUMBER and my eSIM number is shown along with my Freedom description of the eSIM right below it. The Verification Code page appears, but I never get a verification code. I click on DID NOT GET A VERIFICATION CODE? and try trigger a phone call and do not get that either. I've reset my eSIM, I've reset my iPhone's networking, I've rebooted my phone many times, I've un/re-installed the app and TestFlight. I'm willing to try anything here, but is it possible because my personal mo
Replies
3
Boosts
0
Views
481
Activity
May ’26
Reply to StoreKit 2 returns empty products array on device (iPhone) even though IAP is Ready to Submit
Hello - In reviewing your account, it appears that the required Paid Apps Agreement has not been signed and is not yet in the Active state. Because of this, your In-App Purchase products are not available for testing in Sandbox or for purchase in Production. Please direct the Account Holder to accept the Paid Apps Agreement, complete both the Banking and Tax information, and ensure the status of this agreement is updated to ACTIVE. We also recommend completing a successful Sandbox purchase in your app. Please let us know if you have any additional questions or need further assistance. Thank you.
Replies
Boosts
Views
Activity
May ’26
First subscription stuck in "Developer Action Needed", no IAP section on version page, reviewer hits "product is not available for purchase" — works fine on my own TestFlight install
I'm preparing my first App Store submission and have hit a chain of issues that appear to be backend state problems I can't resolve from the App Store Connect UI. I've already opened a DTS case but wanted to ask here in case anyone has seen this combination before. Setup: iOS app with first-time subscriptions (auto-renewable, 7-day free trial) Two products: bitcoinhq_pro_monthly and bitcoinhq_pro_annual Both in the same subscription group Bitcoin HQ Pro Paid Apps Agreement is Active Bundle ID, prices (all 175 territories including United States), intro offers (Free for the first week in all territories), localizations all configured Important context: On my own iPad (TestFlight build, signed into my normal sandbox account), the full flow works perfectly — paywall loads on first launch after install, both products show with correct prices, tapping Subscribe opens the StoreKit sheet, purchase completes, the entitlement grants, and Pro features unlock. So the app code and RevenueCat configuration are wo
Replies
0
Boosts
0
Views
398
Activity
May ’26
Reply to How much practical benefit is there to XPC-based privilege separation?
There are a couple of ways XPC services can help with security. The first is the one you’re talking about, that is, where you give the XPC service elevated privileges. Your ‘delete a user’ example isn’t great though, because deleting arbitrary users is problematic and it also requires BSD privileged escalation. So let’s consider a different example. Consider a sandboxed app that wants to install an item in ~/Library/PDF Services. There are no BSD level blocks to doing that, but it is blocked by the App Sandbox. To get around that block you sign the app with the com.apple.security.temporary-exception.files.home-relative-path.read-write temporary exception entitlement. Cool, problem solved! Note For links to more about temporary exception entitlements, and the App Sandbox in general, see App Sandbox Resources. However, if your app gets compromised then it might install arbitrary stuff into ~/Library/PDF Services, which isn’t great. So instead you move that code into an XPC se
Topic: Privacy & Security SubTopic: General Tags:
Replies
Boosts
Views
Activity
May ’26
Reply to How much practical benefit is there to XPC-based privilege separation?
I was about to respond in a similar fashion. An exploit is typically considered a binary operation. The app is either secure or exploited. XPC Services make that a floating point. The app can be partially exploited, on either the main or the XPC side(s). That both limits the risk and increases the cost of the exploit. However, then you mentioned daemons. That's something completely different. XPC is many different things. It is a communication protocol that can be used by both XPC services and daemons. But XPC services are not the same thing as daemons. XPC services are easy to use and deploy. They give you some flexibility with sandboxing. But there's nothing easy about daemons, including The XPC communication.
Topic: Privacy & Security SubTopic: General Tags:
Replies
Boosts
Views
Activity
May ’26
How much practical benefit is there to XPC-based privilege separation?
Privilege separation is one of the two main reasons to use XPC services given by https://developer.apple.com/library/archive/documentation/MacOSX/Conceptual/BPSystemStartup/Chapters/CreatingXPCServices.html — With traditional applications, if an application becomes compromised through a buffer overflow or other security vulnerability, the attacker gains the ability to do anything that the user can do. To mitigate this risk, Mac OS X provides sandboxing—limiting what types of operations a process can perform. […] Each XPC service has its own sandbox, so XPC services can make it easier to implement proper privilege separation. The idea (iiuc) being that if the main process is compromised, the spicier operations have been separated out to a separate process space, and this improves the security of the system. But if the main process is compromised, and that main process is trusted by the more-privileged XPC service, is not the system still compromised in practice? That is rather than the exploi
Replies
3
Boosts
0
Views
500
Activity
May ’26
Reply to "Unable to Manage Sandbox Test Account - Popup Closes on 'Manage' Click"
I am also getting the same issue using a sandbox testing account, and I have followed the same steps
Replies
Boosts
Views
Activity
May ’26
App Subscription "Confirm with Apple Device" UI
My tvOS app includes the purchase of subscriptions, and I am updating the code with Storekit 2.0. I have seen other apps that present the Confirm with Apple Device UI upon selection of a product, but for me I only ever see an alert confirming the purchase. I have tested this using Xcode storekit data and a sandbox account. I have also attempted using Storekit views and passing the UIWindowScene to the purchase(confirmIn: ) parameter, but neither made any difference. Is there some limitation that prevents that UI from showing in debug builds?
Replies
1
Boosts
0
Views
793
Activity
May ’26
Reply to StoreKit 2: Transaction.all and Transaction.currentEntitlements return empty for valid non-consumable purchases in production
We’ve now conducted additional tests. We have a 10-year-old app with around 800 downloads per day that has already been migrated to StoreKit 2 for quite some time. With real users in the live app, there are no issues — purchases can be made and restored successfully. However, with a sandbox test user while launching the app from Xcode, neither purchasing nor restoring works. In another 13-year-old app with around 1,800 downloads per day, StoreKit 2 works perfectly both live and with the sandbox test user without any issues. All apps use the exact same code for the StoreKit 2 logic and are tested with the same users. Today we will take the risk and submit the app we were originally talking about for review after switching to StoreKit 2, and test whether it works live without any problems.
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
May ’26
Sectigo Public Server Authentication CA DV R36?
When I submit an https web request I receive both of those funny errors. In particular I do not understand what that “Sectigo Public Server Authentication” message represents, perhaps yet another certification for Apple to access the request, when of course by connecting to that web address on Safari produces no errors. Connection error: Error Domain=NSCocoaErrorDomain Code=4099 The connection to service named com.apple.PerfPowerTelemetryClientRegistrationService was invalidated: Connection init failed at lookup with error 159 - Sandbox restriction. UserInfo={NSDebugDescription=The connection to service named com.apple.PerfPowerTelemetryClientRegistrationService was invalidated: Connection init failed at lookup with error 159 - Sandbox restriction.} (+[PPSClientDonation isRegisteredSubsystem:category:]) Permission denied: Maps / SpringfieldUsage (+[PPSClientDonation sendEventWithIdentifier:payload:]) Invalid inputs: payload={ isSPR = 1; } urlstring=https://taxiprofessional.net/***.php proces
Replies
1
Boosts
0
Views
360
Activity
May ’26
App Store Server Notification v2: how to distinguish a resubscription that happened in-app from one that happened in Settings → Subscriptions?
Context We're handling App Store subscriptions on the server side using App Store Server Notification v2. Our pipeline currently identifies each event by transactionId and originalTransactionId. A few notes about our client: Our app is built with Flutter and uses the standard in_app_purchase plugin layer to drive App Store purchases (StoreKit 1 under the hood). We have not migrated to StoreKit 2 on the client yet. We have not been setting SKPayment.applicationUsername on outgoing purchases, so every transaction we've ever produced has appAccountToken: null in its v2 notification. This question is purely about what the server-side notification can tell us, given the current client state above. What we're trying to figure out A user can resubscribe to an expired subscription in two different places: In-app — the user opens our app and re-purchases through our normal in-app purchase flow. App Store — the user goes to Settings → Apple ID → Subscriptions and resubscribes from the system UI, without ever returning
Replies
1
Boosts
0
Views
1.2k
Activity
May ’26
Reply to IOServiceOpen returns kIOReturnError (0xE00002BC) before NewUserClient — DEXT matches and opens pipes successfully
Any pointer to the correct invocation (or a Configuration Profile to enable DriverKit verbose logging) would unblock me. Two points here: I have a post here about IOLog's oddness which is worth reviewing. That post also has the macro that's supposed to log publicly, so you can confirm your logging is doing what it's supposed to do. There was one developer post about DriverKit logging weirdness, which we never heard back on. IF you determine that this is some kind of system bug, then I'd appreciate you filing a bug on this. Quinn's Your Friend the System Log and Recording Private Data in the System Log both cover how you can manage logging redaction in more detail. One detail that alluded to there is that the SystemLogging.System payload lets you disable ALL private data redaction system wide. Expanding on that last point, while I wouldn't leave redaction disabled, particularly on any machine your actually using, that does provide a quick and easy way to see exactly what data was being logged. That can make it
Topic: App & System Services SubTopic: Drivers Tags:
Replies
Boosts
Views
Activity
May ’26
Reply to StoreKit 2: Transaction.all and Transaction.currentEntitlements return empty for valid non-consumable purchases in production
We have been experiencing the same issue for a few days now in two of our apps. Users have reported it via email and through negative App Store reviews. In all of our other apps, in-app purchases are still working without any problems. In our case, the issue affects non-consumable in-app purchases (one-time purchases). In one of the affected apps, we can reproduce the issue with a Sandbox user. The problem occurs not only with StoreKit 2, but also with the old StoreKit implementation. We noticed it because we are currently migrating this app to StoreKit 2. With StoreKit 1, in-app purchases can be restored using restoreCompletedTransactions. But when trying to purchase an in-app purchase that has already been bought, the App Store displays a message saying that the item has already been purchased and asks whether it should be downloaded again for free. However, the download/restore then fails: Printing description of nsError: Error Domain=SKErrorDomain Code=0 Ein unbekannter Fehler ist aufgetreten Use
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
May ’26
"Unable to Manage Sandbox Test Account - Popup Closes on 'Manage' Click"
Issue: Sandbox test account stuck in a loop when trying to access account management Environment: iOS version: [iOS 26.4.2] Device: iPhone 12 Steps to Reproduce: Created sandbox test credentials on Apple Developer site (App Store Connect → Users and Access → Sandbox → Testers) On iPhone, navigated to Settings → Developer → Sandbox Apple Account Clicked Sign In and entered sandbox test email and password Successfully verified using verification codes (both email and phone number) Clicked on the signed-in sandbox account A popup appears with Manage option Clicked Manage Expected Behavior:- Should open sandbox account management interface Actual Behavior:- Popup immediately closes and the same popup reappears. Clicking Manage again produces the same result - an endless loop preventing access to account management. Has anyone encountered this issue with sandbox test accounts? Is there a known workaround or fix for this behavior?
Replies
2
Boosts
0
Views
535
Activity
May ’26