Search results for

“sandbox”

10,542 results found

Post

Replies

Boosts

Views

Activity

Sandboxed app loses iCloud Drive access mid-session on macOS 26 — kernel refuses sandbox extension, FP client rejected (NSFileProviderErrorDomain -2001)
Starting somewhere around macOS 26.3, my sandboxed file manager spontaneously loses access to ~/Library/Mobile Documents mid-session. Setup: at launch, the user grants access to '/', '/Users', or '~' via NSOpenPanel; I store a security-scoped bookmark and call startAccessingSecurityScopedResource(). This works fine - including iCloud Drive - until some point mid-session. When it breaks, two things happen simultaneously: Enumeration fails: NSCocoaErrorDomain Code=257 (NSFileReadNoPermissionError)< NSPOSIXErrorDomain Code=1 (EPERM) Console shows the kernel refusing extension issuance: couldn't issue sandbox extension com.apple.app-sandbox.read for '/Users//Library/Mobile Documents': Operation not permitted And probing NSFileProviderManager confirms the process has been rejected system-wide: NSFileProviderManager.getDomainsWithCompletionHandler > NSFileProviderErrorDomain Code=-2001 The application cannot be used right now. (underlying Code=-2014) What makes this specific to FP-backed pat
3
0
1.1k
Apr ’26
First-time notarization stuck "In Progress" for all submissions
Hello, I'm submitting my first macOS app for notarization from a new Developer ID team. All three submissions have been stuck at In Progress for several hours now. notarytool log returns Submission log is not yet available for all of them. Submission IDs: 39856e43-46ee-45ed-b1c7-771fb6603258 (submitted 2026-04-18T10:00 UTC) 3edf2f4f-cbaf-4e14-ba3b-c1b4e111827e (submitted 2026-04-18T10:03 UTC) 858c52e7-3386-41a8-8fee-a31c49980319 (submitted 2026-04-18T10:25 UTC) Details: This is the first notarization attempt for this Developer ID team App is signed with Developer ID Application certificate, hardened runtime enabled codesign --verify --deep --strict passes All nested code (including Sparkle framework helpers) is properly signed Only public system frameworks are linked (IOKit, AppKit, Foundation, etc.) Entitlements: app-sandbox + Sparkle mach-lookup exceptions only No private API usage Is this expected for first-time submissions, or could someone check the backend queue status for these submissions? An
2
0
560
Apr ’26
Reply to [Catalina] Quick Look doesn't extend Sandbox for "related items"
More than 7 years later and the issue still exists - even with Preview / Thumbnail extensions: NSFileCoordinator / NSFilePresenter are used (and working with the apps on macOS and iOS), but Console.app is reporting a sandbox violation once a file with related items (sidecar files) is previewed. Unfortunately, no comment from Apple at all, not even a works as designed - what would be strange as the behavior was broken with macOS 10.15...
Topic: UI Frameworks SubTopic: AppKit Tags:
Apr ’26
Unable to load App into TestFlight
This is my first in-App purchase App. I have other paid Apps and my business status are all active. I tested the in-app purchases on my devices using a StoreKit file and Xcode. I removed the StoreKit file from run configuration Scheme, I added in-app purchases to Signing & Capabilities then archived, validated and uploaded build to AppStore connect. I added two testers - a sandbox account (gmail subaddressed) and another gmail account. When I try to load the App using TestFlight I immediately get couldn't load App. This is an App that previously had no in-app purchases. I added in-app after version 1 (tested ok in TestFlight). Now trying to test version 3 in TestFlight. Any insight would be appreciated.
0
0
184
Apr ’26
Keyboard focus lost after instantiating an AUv3 in a host on iOS
Dear Apple Support team, I'm reaching out about an issue we're facing in our iOS audio host app on iPad. Keyboard shortcuts from an external hardware keyboard (Bluetooth) work perfectly until we load an AUv3 plugin, then the host suddenly loses all keyboard focus, and key commands stop responding completely. To give you more context: this affects every DAW that supports AUv3. I've tested it in Logic Pro for iOS, Camelot Pro, and AUM. The problem starts right after instantiating any AUv3, causing the keyboard to lose focus and preventing key commands from working. Before that, keyboard events reach our UIView without issues. Notably, this doesn't happen on iOS versions before iOS 26. I've verified it works perfectly on iOS 17 and iOS 18. You can see the full discussion and steps to reproduce in this JUCE forum thread: https://forum.juce.com/t/keyboard-focus-lost-and-keycommands-stop-working-after-instantiating-an-auv3-in-a-juce-based-host-on-ios/68497/5. It seems potentially related to AUv3 sandboxing
Topic: UI Frameworks SubTopic: UIKit
2
0
418
Apr ’26
Reply to HID Device Access / Mode Switch
Is there any way at all to do this on macOS? I'm not sure exactly which APIs you're interacting with and how that translates to the specific failure you're seeing, so I'm going to outline what should work. Give it a try and then we can dig into the specifics of any issue you run into. Getting into the details: You should be using the IOUSBHost Framework, which is the modern framework for interacting with USB devices from user space. I'll assume you already know how to find your target in the IORegistry, but please let me know if you need guidance on that. You should be looking and connecting to the IOUSBHostDevice, NOT the https://developer.apple.com/documentation/iousbhost/iousbhostinterface?language=objc. That gives you full control over the accessory and removes all other drivers, which is what you want for a firmware updater. When you create your host object, you'll need to pass in the IOUSBHostObjectInitOptionsDeviceCapture option. You can also try IOUSBHostObjectInitOptionsDeviceSeize, but I think captu
Topic: App & System Services SubTopic: Drivers Tags:
Apr ’26
Given up on the AppStore
After waiting for review, making changes, then stuck In Review, I made the major decision to pull my pro audio application from the App Store before it was even accepted. The friction generated from Apple's process is not worth what you are getting back. Consequently, the offering for audio in the Mac App Store itself look very amateur and are largely limited to toys. This is an uninspiring group to be associated with and given the delays, cost, and hamstringing due to sandboxing, the motivation to follow through is very low. I would encourage Apple to rethink their macOS approach if they actually want developers to use this system. This has been an issue for many years, and the situation is not improved. I thought I'd try again this round, but have again given up on the wait and restrictions.
0
0
62
Apr ’26
Reply to How to reset user preference for crypto token kit access
My main goal was to use Authentication Services but it requires the device to be managed via mobile device management. For non-managed devices, I was looking to create an extension that all apps on the device can talk to silently using CTK for tokens in the CTK host app's possession. In iOS, with the sandbox restrictions, as you pointed out, only apps hosting their extensions can talk to it via XPC. iOS26 introduced some APIs in extensionKit to add an interactive view for users. I was hoping, as a developer I can control the messaging in the consent prompt that shows up when an app tries to access tokens using CTK the first time. The best path would be to open up XPC communication across apps using extensionKit in iOS but that is Apple's decision to make :) Or remove the device management prequisite to use Single-sign on extension in Authentication Services.
Topic: Privacy & Security SubTopic: General Tags:
Apr ’26
Reply to Wrong value for storekit custom purchase link allowed regions entitlement
Please submit a feedback assistant ticket at (http://feedbackassistant.apple.com). Please provide as much information as possible, ie a sysdiagnose, app apple ID, in-app apple IDs, sandbox account apple ID (if applicable), transactions IDs, steps to reproduce and other relevant details. File ticket under iOS & iPadOS, macOS, tvOS, watchOS, or visionOS and ensure you select “App Store” for the question “Which area are you seeing an issue with?” Categorize the type of feedback Please attach all available files needed to verify After submitting the feedback, please regularly check the ticket as we'll only communicate through it from then on. Once you open the Feedback Assistant Ticket report, please post the FB number here for reference. If you have any questions about filing a report, take a look at Bug Reporting: How and Why (https://developer.apple.com/forums/thread/712889)?
Topic: App & System Services SubTopic: StoreKit Tags:
Apr ’26
Reply to WatchOS IAP -- why is this such a mess?
Please submit a feedback assistant ticket at (http://feedbackassistant.apple.com). Please provide as much information as possible, ie a sysdiagnose, app apple ID, in-app apple IDs, sandbox account apple ID (if applicable), transactions IDs, steps to reproduce and other relevant details. File ticket under iOS & iPadOS, macOS, tvOS, watchOS, or visionOS and ensure you select “App Store” for the question “Which area are you seeing an issue with?” Categorize the type of feedback Please attach all available files needed to verify After submitting the feedback, please regularly check the ticket as we'll only communicate through it from then on. Once you open the Feedback Assistant Ticket report, please post the FB number here for reference. If you have any questions about filing a report, take a look at Bug Reporting: How and Why (https://developer.apple.com/forums/thread/712889)?
Topic: App & System Services SubTopic: StoreKit Tags:
Apr ’26
Reply to StoreKit Subscription not discoverable in App Review (PLEASE HELP!))
Please submit a feedback assistant ticket at (http://feedbackassistant.apple.com). Please provide as much information as possible, ie a sysdiagnose, app apple ID, in-app apple IDs, sandbox account apple ID (if applicable), transactions IDs, steps to reproduce and other relevant details. File ticket under iOS & iPadOS, macOS, tvOS, watchOS, or visionOS and ensure you select “App Store” for the question “Which area are you seeing an issue with?” Categorize the type of feedback Please attach all available files needed to verify After submitting the feedback, please regularly check the ticket as we'll only communicate through it from then on. Once you open the Feedback Assistant Ticket report, please post the FB number here for reference. If you have any questions about filing a report, take a look at Bug Reporting: How and Why?
Apr ’26
Store Kit 2 iOS system purchase confirmation dialog not consistent.
I'm running into an issue where it appears the product transaction is being cached and not showing a new iOS system popup dialog to confirm the purchase. This is affecting testing, and I need a solution to have iOS issue a new purchase transaction every time. Here's what happens, I call the following which always succeeds. try await product.purchase(options: [.appAccountToken(appToken)]) I'm signed into a developer sandbox account with a resubscribe every 5 minutes. After cancelling a subscription, I attempt to resubscribe using the same code as above. Frequently, the code executes without iOS showing the popup system dialog to confirm the purchaser. After waiting a period of time, iOS then resets itself and allows me to purchase again. What I want is an option the forces the iOS system confirm purchase dialog to show up every time the code executes. How do I fix this? iOs 26.4.1, iPhone 17 Pro.
2
0
546
Apr ’26
Reply to Approval of first in-App purchase
is this the way to get your first in-App purchase approved? If you still need to test your In-App Purchase, then there is no need to submit them for review yet. Testing In-App Purchase in the Apple sandbox environment doesn’t require you submit your In-App Purchases for review. TestFlight also uses the sandbox for In-App Purchases. Apple reviews your In-App Purchases in the same environment. However, if you are done with testing, submit your In-App Purchase for review. all works in Xcode. If you enable StoreKit Testing in Xcode, you likely tested your products in the local environment. To test in the sandbox, disable StoreKit Testing in Xcode, then follow the steps in Testing In-App Purchases with sandbox to test your products in the sandbox. Be sure to read TN3186: Troubleshooting In-App Purchases availability in the sandbox that identifies common configurations that make your In-App Purchases unavailable in the sandbox environment.
Apr ’26
Sandboxed app loses iCloud Drive access mid-session on macOS 26 — kernel refuses sandbox extension, FP client rejected (NSFileProviderErrorDomain -2001)
Starting somewhere around macOS 26.3, my sandboxed file manager spontaneously loses access to ~/Library/Mobile Documents mid-session. Setup: at launch, the user grants access to '/', '/Users', or '~' via NSOpenPanel; I store a security-scoped bookmark and call startAccessingSecurityScopedResource(). This works fine - including iCloud Drive - until some point mid-session. When it breaks, two things happen simultaneously: Enumeration fails: NSCocoaErrorDomain Code=257 (NSFileReadNoPermissionError)< NSPOSIXErrorDomain Code=1 (EPERM) Console shows the kernel refusing extension issuance: couldn't issue sandbox extension com.apple.app-sandbox.read for '/Users//Library/Mobile Documents': Operation not permitted And probing NSFileProviderManager confirms the process has been rejected system-wide: NSFileProviderManager.getDomainsWithCompletionHandler > NSFileProviderErrorDomain Code=-2001 The application cannot be used right now. (underlying Code=-2014) What makes this specific to FP-backed pat
Replies
3
Boosts
0
Views
1.1k
Activity
Apr ’26
First-time notarization stuck "In Progress" for all submissions
Hello, I'm submitting my first macOS app for notarization from a new Developer ID team. All three submissions have been stuck at In Progress for several hours now. notarytool log returns Submission log is not yet available for all of them. Submission IDs: 39856e43-46ee-45ed-b1c7-771fb6603258 (submitted 2026-04-18T10:00 UTC) 3edf2f4f-cbaf-4e14-ba3b-c1b4e111827e (submitted 2026-04-18T10:03 UTC) 858c52e7-3386-41a8-8fee-a31c49980319 (submitted 2026-04-18T10:25 UTC) Details: This is the first notarization attempt for this Developer ID team App is signed with Developer ID Application certificate, hardened runtime enabled codesign --verify --deep --strict passes All nested code (including Sparkle framework helpers) is properly signed Only public system frameworks are linked (IOKit, AppKit, Foundation, etc.) Entitlements: app-sandbox + Sparkle mach-lookup exceptions only No private API usage Is this expected for first-time submissions, or could someone check the backend queue status for these submissions? An
Replies
2
Boosts
0
Views
560
Activity
Apr ’26
Reply to [Catalina] Quick Look doesn't extend Sandbox for "related items"
More than 7 years later and the issue still exists - even with Preview / Thumbnail extensions: NSFileCoordinator / NSFilePresenter are used (and working with the apps on macOS and iOS), but Console.app is reporting a sandbox violation once a file with related items (sidecar files) is previewed. Unfortunately, no comment from Apple at all, not even a works as designed - what would be strange as the behavior was broken with macOS 10.15...
Topic: UI Frameworks SubTopic: AppKit Tags:
Replies
Boosts
Views
Activity
Apr ’26
Reply to process.waitUntilExit never exits in tahoe 26.3
utm app uses this method https://github.com/utmapp/UTM/blob/30c8202c630c5af2e3c3403df1bb95c962459bc6/Services/UTMASIFImage.m#L18 is it allowed in sandboxed environment?
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
Apr ’26
Unable to load App into TestFlight
This is my first in-App purchase App. I have other paid Apps and my business status are all active. I tested the in-app purchases on my devices using a StoreKit file and Xcode. I removed the StoreKit file from run configuration Scheme, I added in-app purchases to Signing & Capabilities then archived, validated and uploaded build to AppStore connect. I added two testers - a sandbox account (gmail subaddressed) and another gmail account. When I try to load the App using TestFlight I immediately get couldn't load App. This is an App that previously had no in-app purchases. I added in-app after version 1 (tested ok in TestFlight). Now trying to test version 3 in TestFlight. Any insight would be appreciated.
Replies
0
Boosts
0
Views
184
Activity
Apr ’26
Keyboard focus lost after instantiating an AUv3 in a host on iOS
Dear Apple Support team, I'm reaching out about an issue we're facing in our iOS audio host app on iPad. Keyboard shortcuts from an external hardware keyboard (Bluetooth) work perfectly until we load an AUv3 plugin, then the host suddenly loses all keyboard focus, and key commands stop responding completely. To give you more context: this affects every DAW that supports AUv3. I've tested it in Logic Pro for iOS, Camelot Pro, and AUM. The problem starts right after instantiating any AUv3, causing the keyboard to lose focus and preventing key commands from working. Before that, keyboard events reach our UIView without issues. Notably, this doesn't happen on iOS versions before iOS 26. I've verified it works perfectly on iOS 17 and iOS 18. You can see the full discussion and steps to reproduce in this JUCE forum thread: https://forum.juce.com/t/keyboard-focus-lost-and-keycommands-stop-working-after-instantiating-an-auv3-in-a-juce-based-host-on-ios/68497/5. It seems potentially related to AUv3 sandboxing
Topic: UI Frameworks SubTopic: UIKit
Replies
2
Boosts
0
Views
418
Activity
Apr ’26
Reply to HID Device Access / Mode Switch
Is there any way at all to do this on macOS? I'm not sure exactly which APIs you're interacting with and how that translates to the specific failure you're seeing, so I'm going to outline what should work. Give it a try and then we can dig into the specifics of any issue you run into. Getting into the details: You should be using the IOUSBHost Framework, which is the modern framework for interacting with USB devices from user space. I'll assume you already know how to find your target in the IORegistry, but please let me know if you need guidance on that. You should be looking and connecting to the IOUSBHostDevice, NOT the https://developer.apple.com/documentation/iousbhost/iousbhostinterface?language=objc. That gives you full control over the accessory and removes all other drivers, which is what you want for a firmware updater. When you create your host object, you'll need to pass in the IOUSBHostObjectInitOptionsDeviceCapture option. You can also try IOUSBHostObjectInitOptionsDeviceSeize, but I think captu
Topic: App & System Services SubTopic: Drivers Tags:
Replies
Boosts
Views
Activity
Apr ’26
Given up on the AppStore
After waiting for review, making changes, then stuck In Review, I made the major decision to pull my pro audio application from the App Store before it was even accepted. The friction generated from Apple's process is not worth what you are getting back. Consequently, the offering for audio in the Mac App Store itself look very amateur and are largely limited to toys. This is an uninspiring group to be associated with and given the delays, cost, and hamstringing due to sandboxing, the motivation to follow through is very low. I would encourage Apple to rethink their macOS approach if they actually want developers to use this system. This has been an issue for many years, and the situation is not improved. I thought I'd try again this round, but have again given up on the wait and restrictions.
Replies
0
Boosts
0
Views
62
Activity
Apr ’26
Reply to How to reset user preference for crypto token kit access
My main goal was to use Authentication Services but it requires the device to be managed via mobile device management. For non-managed devices, I was looking to create an extension that all apps on the device can talk to silently using CTK for tokens in the CTK host app's possession. In iOS, with the sandbox restrictions, as you pointed out, only apps hosting their extensions can talk to it via XPC. iOS26 introduced some APIs in extensionKit to add an interactive view for users. I was hoping, as a developer I can control the messaging in the consent prompt that shows up when an app tries to access tokens using CTK the first time. The best path would be to open up XPC communication across apps using extensionKit in iOS but that is Apple's decision to make :) Or remove the device management prequisite to use Single-sign on extension in Authentication Services.
Topic: Privacy & Security SubTopic: General Tags:
Replies
Boosts
Views
Activity
Apr ’26
Reply to Wrong value for storekit custom purchase link allowed regions entitlement
Please submit a feedback assistant ticket at (http://feedbackassistant.apple.com). Please provide as much information as possible, ie a sysdiagnose, app apple ID, in-app apple IDs, sandbox account apple ID (if applicable), transactions IDs, steps to reproduce and other relevant details. File ticket under iOS & iPadOS, macOS, tvOS, watchOS, or visionOS and ensure you select “App Store” for the question “Which area are you seeing an issue with?” Categorize the type of feedback Please attach all available files needed to verify After submitting the feedback, please regularly check the ticket as we'll only communicate through it from then on. Once you open the Feedback Assistant Ticket report, please post the FB number here for reference. If you have any questions about filing a report, take a look at Bug Reporting: How and Why (https://developer.apple.com/forums/thread/712889)?
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Apr ’26
Reply to WatchOS IAP -- why is this such a mess?
Please submit a feedback assistant ticket at (http://feedbackassistant.apple.com). Please provide as much information as possible, ie a sysdiagnose, app apple ID, in-app apple IDs, sandbox account apple ID (if applicable), transactions IDs, steps to reproduce and other relevant details. File ticket under iOS & iPadOS, macOS, tvOS, watchOS, or visionOS and ensure you select “App Store” for the question “Which area are you seeing an issue with?” Categorize the type of feedback Please attach all available files needed to verify After submitting the feedback, please regularly check the ticket as we'll only communicate through it from then on. Once you open the Feedback Assistant Ticket report, please post the FB number here for reference. If you have any questions about filing a report, take a look at Bug Reporting: How and Why (https://developer.apple.com/forums/thread/712889)?
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Apr ’26
Reply to StoreKit Subscription not discoverable in App Review (PLEASE HELP!))
Please submit a feedback assistant ticket at (http://feedbackassistant.apple.com). Please provide as much information as possible, ie a sysdiagnose, app apple ID, in-app apple IDs, sandbox account apple ID (if applicable), transactions IDs, steps to reproduce and other relevant details. File ticket under iOS & iPadOS, macOS, tvOS, watchOS, or visionOS and ensure you select “App Store” for the question “Which area are you seeing an issue with?” Categorize the type of feedback Please attach all available files needed to verify After submitting the feedback, please regularly check the ticket as we'll only communicate through it from then on. Once you open the Feedback Assistant Ticket report, please post the FB number here for reference. If you have any questions about filing a report, take a look at Bug Reporting: How and Why?
Replies
Boosts
Views
Activity
Apr ’26
Store Kit 2 iOS system purchase confirmation dialog not consistent.
I'm running into an issue where it appears the product transaction is being cached and not showing a new iOS system popup dialog to confirm the purchase. This is affecting testing, and I need a solution to have iOS issue a new purchase transaction every time. Here's what happens, I call the following which always succeeds. try await product.purchase(options: [.appAccountToken(appToken)]) I'm signed into a developer sandbox account with a resubscribe every 5 minutes. After cancelling a subscription, I attempt to resubscribe using the same code as above. Frequently, the code executes without iOS showing the popup system dialog to confirm the purchaser. After waiting a period of time, iOS then resets itself and allows me to purchase again. What I want is an option the forces the iOS system confirm purchase dialog to show up every time the code executes. How do I fix this? iOs 26.4.1, iPhone 17 Pro.
Replies
2
Boosts
0
Views
546
Activity
Apr ’26
Reply to Approval of first in-App purchase
is this the way to get your first in-App purchase approved? If you still need to test your In-App Purchase, then there is no need to submit them for review yet. Testing In-App Purchase in the Apple sandbox environment doesn’t require you submit your In-App Purchases for review. TestFlight also uses the sandbox for In-App Purchases. Apple reviews your In-App Purchases in the same environment. However, if you are done with testing, submit your In-App Purchase for review. all works in Xcode. If you enable StoreKit Testing in Xcode, you likely tested your products in the local environment. To test in the sandbox, disable StoreKit Testing in Xcode, then follow the steps in Testing In-App Purchases with sandbox to test your products in the sandbox. Be sure to read TN3186: Troubleshooting In-App Purchases availability in the sandbox that identifies common configurations that make your In-App Purchases unavailable in the sandbox environment.
Replies
Boosts
Views
Activity
Apr ’26
Reply to In-App Purchase works in TestFlight but fails during App Review (Apple can't complete purchase)
To debug your issue, see TN3186: Troubleshooting In-App Purchases availability in the sandbox.
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
Apr ’26