Search results for

“sandbox”

10,540 results found

Post

Replies

Boosts

Views

Activity

Sandbox test notification returns 4040007 after notification URL is saved and verified
For our app, we saved a sandbox App Store Server Notifications URL with V2 enabled and independently read the configuration back. A subsequent test-notification request returned HTTP 404 / 4040007. An authenticated sandbox notification-history request shortly beforehand returned HTTP 200. We restored the original settings after collecting diagnostics. The recorded failure is covered by Feedback Assistant report FB24885397. What could explain this discrepancy, and what additional diagnostics would help Apple investigate?
0
0
129
1w
Reply to AlarmKit: supported approach for a server-triggered wake-up alarm after an air-raid all-clear
I have not tested whether this can be done in an NSE. Various extensions have differing sandbox limitations on what functionality would be enabled. That's why I suggested to try it out yourselves as an experiment. While you won't be able to send actual push notifications using a free account, you can use a JSON file containing your payload in the simulator. This will still let you test your AlarmKit interaction inside the NSE, and at the very least let you know if this is a viable architecture to consider. You would create a JSON file as such: { Simulator Target Bundle: com.airraidapp.test, aps: { alert: { title: Airraid Update, body: Airraids are over }, mutable-content: 1 } } and call it airraid.apns (or whatever you want, just match your BundleID in the payload to your app) And then either drag and drop this onto the simulator to simulate a push, or use xcrun from a Terminal. xcrun simctl push --help shows the usage. Good luck! -- S.Beck -- 7strikes.dev
1w
macOS content filter: supported denial guarantee across provider failure for a bounded process tree
We are designing a bounded local macOS operation with a supervisor, controller and helper. All three must be unable to cause prohibited network effects, including attributable delegated requests, before admission and until quiescence. Unrelated applications must retain their normal network access. We are seeking an API contract clarification, not reporting a reproduced OS bug. No NetworkExtension provider has been activated for this design. Our reviewed SDK is MacOSX27.0.sdk; its presence is not a runtime qualification. Please identify the supported macOS versions for your answer. The design must tolerate provider crash, termination, disconnection and unresponsiveness, and operation lease expiry/revocation. Administrative filter disablement or privileged reconfiguration is a separate unresolved threat-model case, not something we assume ordinary failure handling covers. We reviewed content-filter deployment in TN3134 and the nullable/delegated audit tokens in NEFilterFlow. We understand that NEURLFilterManage
3
0
164
1w
StoreKit 2 Product.products(for:) returns empty array without error on device and TestFlight
Hello, I’m investigating subscription product discovery in my iOS app, BiteTempo. StoreKit 2 completes the product request successfully but returns an empty array for both auto-renewable subscriptions. The issue occurs on a physical iPhone running through Xcode and also in TestFlight. App and products Bundle ID: shehan.NouriJournal App version: 1.0 (4) Monthly: shehan.NouriJournal.plus.monthly Annual: shehan.NouriJournal.plus.annual Reported storefront: USA Device system version reported in diagnostics: 26.6.1 (23G83) Reproduction Run the app on a physical iPhone through Xcode with StoreKit Configuration set to None. Open the subscription paywall. Request both products using Product.products(for:). Inspect the returned array immediately after the awaited call, before filtering. At that breakpoint, returnedProducts contains 0 values. The empty result is not created by application filtering or by converting a caught error into an empty array. Errors are reported separately. Diagnostic output from the Xcode devi
0
0
176
1w
Reply to Crashing in sandbox-exec (FB16964888)
Just a quick follow-up here. macOS 27 introduced an alternative approach for third-party developers to sandbox child processes, namely the es_new_descendants_client mechanism within Endpoint Security. If you find yourself reaching for sandbox-exec and custom SBPL code — techniques that are, as I mentioned above, unsupported by DTS — you should consider that alternative. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Topic: Privacy & Security SubTopic: General Tags:
1w
Reply to SecItemAdd returns OSStatus 100001 from JXA launched by a sandboxed development tool
Thanks for all that info. I did some digging and my best guess is that Codex is applying a custom sandbox, using sandbox-exec and their own SBPL code. We don’t support that, for the reason I explain in this thread. Given that, there are limits to how much I can help you here. I suspect that your JAX code is inheriting this custom sandbox from Codex, and that’s the root cause of this problem. And that has a couple of negative consequences: I can’t help you with your problem, because I’ve no idea how Codex has set up this sandbox. I normally encourage folks who are having problems like this to contact their tooling vendor and, if necessary, the tooling vendor can seek help from Apple. However, that won’t work in this case because we can’t help them with SBPL [1]. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com [1] Our advice for folks who want to implement custom sandboxing is to lean in to the es_n
Topic: Privacy & Security SubTopic: General Tags:
1w
Reply to Supported lifecycle and termination guarantees for an embedded macOS XPC service
[quote='906868022, Alihan1, /thread/847615?answerId=906868022#906868022, /profile/Alihan1'] its embedded XPC service before the service sends its first message [/quote] Hmmmm, this question seems backwards to me. An XPC service is launched in response to an XPC message on its named endpoint. So are you worried about the service sending its reply to that message? Or about the service talking to some other XPC service while processing that first message? The way you’ve phrased this question is very reminiscent of this thread, where the developer was trying to sandbox a child process. And my advice for those folks was to lean in to the new es_new_descendants_client feature. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
1w
-paymentQueue:updatedTransactions: called continuously every time app is in foreground
-(void)paymentQueue:(SKPaymentQueue*)queue updatedTransactions:(NSArray*)transactions In the sandbox environment this is called continuously every time my enters the foreground. I call -finishTransaction on approximately 22 transactions. Confirmed by: NSUInteger finishCount = 0; NSUInteger transactionCount = transactions.count; for (SKPaymentTransaction *aTransaction in transactions) { // Check state..if purchased or restored.. [[SKPaymentQueue defaultQueue]finishTransaction:aTransaction]; finishCount++; // Post notification telling everyone here! } NSLog(@Finsihed %lu of %lu,finishCount,transactionCount); The log at the bottom says - finished 22 of 22 transactions. But every time the app enters the foreground the -paymentQueue:updatedTransactions: is called again with another batch of transactions. How Over and over again. Not sure how this is possible but the transactions seem to never clear from the queue. I hope this may be limited to the sandboxed environment. In this loop after finish
0
0
231
1w
Reply to Sandboxed SMAppService LaunchDaemon: supported identity and persistent storage?
So, before we get to the technical question here, there’s the concern that Etresoft raised. If the goal of sandboxing your daemon is so that you can ship this product on the Mac App Store, it’s not at all clear as to whether that’ll work. While SMAppService is capable of installing a sandboxed daemon from a sandboxed app [1], App Review has traditionally taken a dim view of Mac App Store apps that try to escalate privileges. OTOH, they do allow code to run as root in at least one case, namely Network Extension providers that are packaged as a system extension [2]. I recommend that you talk to App Review to see if they have any guidance here. Coming back to the technical aspects of this, I don’t think it’s feasible to change user ID in a sandboxed daemon. The App Sandbox was designed for apps, and apps can’t change user ID. There’s precedent for enabling App Sandbox in a daemon [3] but those don’t change user ID. Critically, the App Sandbox has ver
Topic: App & System Services SubTopic: Core OS Tags:
1w
400 error is returned for the request sent to the External Purchase Server API.
Hello. I am having trouble because when I send a request to the External Purchase Server API from my own server, I receive a 400 error, but the response does not specify a reason. ・Sent data (some information is masked with ) marketplaceToken received from the client: eyJhcHBBcHBsZUlkIjo2NzU5MTg2MjcyLCJidW5kbGVJZCI6ImNvbS5IYWJiaXQuQW5hRG9zLlBh**************************************************************************************************************************************************************************************************************************CJ0b2tlblR5cGUiOiJDT1JFX1RFQ0hOT0xPR1kifQ== The content of the Bearer Token used when performing a cancellation operation for this payment transaction: {iss:a5******---****-3c08,iat:1790134367,exp:1790135567,aud:appstoreconnect-v1,bid:com...Pal} The JWT actually sent: eyJ0eXAiOiJKV1QiLCJhbGciOiJFUzI1NiIsImtpZCI6Ikg5N1dOOTRLNjYifQ.eyJpc3MiOiJhNTU******************************************************************************************************************
0
0
57
2w
ExternalPurchaseCustomLink.isEligible always returns false in Japan Sandbox
ExternalPurchaseCustomLink.isEligible always returns false although the documented Japan requirements are satisfied. Environment: iPhone, iOS 26.7 Bundle ID: com.audio.yoho.ios Storefront: JPN (143462) Japan Sandbox account canMakePayments: true AppTransaction: Sandbox, verified Signed entitlement: com.apple.developer.storekit.custom-purchase-link.allowed-regions = [jp] ExternalPurchase.canPresent also returns false. Has anyone successfully tested this API in a development-signed Sandbox build? Feedback Assistant: ExternalPurchaseCustomLink.isEligible always returns false although the documented Japan requirements are satisfied. Environment: iPhone, iOS 26.7 Bundle ID: com.audio.yoho.ios Storefront: JPN (143462) Japan Sandbox account canMakePayments: true AppTransaction: Sandbox, verified Signed entitlement: com.apple.developer.storekit.custom-purchase-link.allowed-regions = [jp] ExternalPurchase.canPresent also returns false. Has anyone successfully tested this AP
0
0
291
2w
Reply to Security Concern : Clarification on iOS App Switcher Snapshot Storage and User Accessibility
1.Where exactly are these App Switcher preview screenshots stored on the device filesystem? I'm not sure, as I've never specifically looked for them. 2.Can these App Switcher snapshots be accessed on a jailbroken iOS device? Yes, that's very likely. 3.Are these snapshots stored inside the application container No. or in a system-managed location outside the app sandbox? Yes. Can any Third party application or tool can access this screenshots in iOS device? Ignoring jail broken device, no. 5.Is there any Apple-recommended API, entitlement, or platform-supported mechanism on iOS to prevent screenshots in iOS Sure. SwiftUI has the privacySensitive(_:) view modifier, which basically handles this automatically. UIKit apps typically handled this using a different view to hide their actual view, triggered by either resignation or backgrounding. __ Kevin Elliott DTS Engineer, CoreOS/Hardware
Topic: UI Frameworks SubTopic: General Tags:
2w
Reply to Can a Mac App Store app open a bundled, signed MCPB for installation in Claude Desktop?
Thanks, that’s helpful regarding replies vs comments and Meet with Apple. Just to clarify, my concern is not a generic “will App Review like my app?” question. I’m trying to verify one specific distribution boundary before finalizing the onboarding flow: whether a sandboxed Mac App Store app may include its own pre-signed .mcpb Desktop Extension as a bundled resource and, after an explicit user action, open that resource using standard macOS APIs so Claude Desktop presents its own native installation and consent UI. The app would not silently install anything, modify Claude’s configuration, automate its UI, download executable code, or bypass user consent. I’ve already submitted the same narrow question to Apple Developer Support. I’m mainly trying to determine whether this pattern is something Apple has previously accepted or whether there is a specific guideline that would prohibit it.
2w
Reply to CTFontManagerCreateFontRequestRunLoopSource does not receive events in macOS 27
It will be a few days before I can test that on 13-26 and remove the XPC service. An unsandboxed launch agent contained in a sandboxed app does seem to work, with XPC, on versions 13, 15, and 27. Haven't tested the other versions. I'm unaware of any specific change over the past two years to get sandboxed XPC working to this extent. Obviously this isn't for the Mac App Store. But it will simplify things. Ironically enough, now I can get rid of a bunch of XPC.
Topic: App & System Services SubTopic: General Tags:
2w
Sandbox test notification returns 4040007 after notification URL is saved and verified
For our app, we saved a sandbox App Store Server Notifications URL with V2 enabled and independently read the configuration back. A subsequent test-notification request returned HTTP 404 / 4040007. An authenticated sandbox notification-history request shortly beforehand returned HTTP 200. We restored the original settings after collecting diagnostics. The recorded failure is covered by Feedback Assistant report FB24885397. What could explain this discrepancy, and what additional diagnostics would help Apple investigate?
Replies
0
Boosts
0
Views
129
Activity
1w
Reply to AlarmKit: supported approach for a server-triggered wake-up alarm after an air-raid all-clear
I have not tested whether this can be done in an NSE. Various extensions have differing sandbox limitations on what functionality would be enabled. That's why I suggested to try it out yourselves as an experiment. While you won't be able to send actual push notifications using a free account, you can use a JSON file containing your payload in the simulator. This will still let you test your AlarmKit interaction inside the NSE, and at the very least let you know if this is a viable architecture to consider. You would create a JSON file as such: { Simulator Target Bundle: com.airraidapp.test, aps: { alert: { title: Airraid Update, body: Airraids are over }, mutable-content: 1 } } and call it airraid.apns (or whatever you want, just match your BundleID in the payload to your app) And then either drag and drop this onto the simulator to simulate a push, or use xcrun from a Terminal. xcrun simctl push --help shows the usage. Good luck! -- S.Beck -- 7strikes.dev
Replies
Boosts
Views
Activity
1w
macOS content filter: supported denial guarantee across provider failure for a bounded process tree
We are designing a bounded local macOS operation with a supervisor, controller and helper. All three must be unable to cause prohibited network effects, including attributable delegated requests, before admission and until quiescence. Unrelated applications must retain their normal network access. We are seeking an API contract clarification, not reporting a reproduced OS bug. No NetworkExtension provider has been activated for this design. Our reviewed SDK is MacOSX27.0.sdk; its presence is not a runtime qualification. Please identify the supported macOS versions for your answer. The design must tolerate provider crash, termination, disconnection and unresponsiveness, and operation lease expiry/revocation. Administrative filter disablement or privileged reconfiguration is a separate unresolved threat-model case, not something we assume ordinary failure handling covers. We reviewed content-filter deployment in TN3134 and the nullable/delegated audit tokens in NEFilterFlow. We understand that NEURLFilterManage
Replies
3
Boosts
0
Views
164
Activity
1w
StoreKit 2 Product.products(for:) returns empty array without error on device and TestFlight
Hello, I’m investigating subscription product discovery in my iOS app, BiteTempo. StoreKit 2 completes the product request successfully but returns an empty array for both auto-renewable subscriptions. The issue occurs on a physical iPhone running through Xcode and also in TestFlight. App and products Bundle ID: shehan.NouriJournal App version: 1.0 (4) Monthly: shehan.NouriJournal.plus.monthly Annual: shehan.NouriJournal.plus.annual Reported storefront: USA Device system version reported in diagnostics: 26.6.1 (23G83) Reproduction Run the app on a physical iPhone through Xcode with StoreKit Configuration set to None. Open the subscription paywall. Request both products using Product.products(for:). Inspect the returned array immediately after the awaited call, before filtering. At that breakpoint, returnedProducts contains 0 values. The empty result is not created by application filtering or by converting a caught error into an empty array. Errors are reported separately. Diagnostic output from the Xcode devi
Replies
0
Boosts
0
Views
176
Activity
1w
Reply to Crashing in sandbox-exec (FB16964888)
Just a quick follow-up here. macOS 27 introduced an alternative approach for third-party developers to sandbox child processes, namely the es_new_descendants_client mechanism within Endpoint Security. If you find yourself reaching for sandbox-exec and custom SBPL code — techniques that are, as I mentioned above, unsupported by DTS — you should consider that alternative. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Topic: Privacy & Security SubTopic: General Tags:
Replies
Boosts
Views
Activity
1w
Reply to SecItemAdd returns OSStatus 100001 from JXA launched by a sandboxed development tool
Thanks for all that info. I did some digging and my best guess is that Codex is applying a custom sandbox, using sandbox-exec and their own SBPL code. We don’t support that, for the reason I explain in this thread. Given that, there are limits to how much I can help you here. I suspect that your JAX code is inheriting this custom sandbox from Codex, and that’s the root cause of this problem. And that has a couple of negative consequences: I can’t help you with your problem, because I’ve no idea how Codex has set up this sandbox. I normally encourage folks who are having problems like this to contact their tooling vendor and, if necessary, the tooling vendor can seek help from Apple. However, that won’t work in this case because we can’t help them with SBPL [1]. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com [1] Our advice for folks who want to implement custom sandboxing is to lean in to the es_n
Topic: Privacy & Security SubTopic: General Tags:
Replies
Boosts
Views
Activity
1w
Reply to Supported lifecycle and termination guarantees for an embedded macOS XPC service
[quote='906868022, Alihan1, /thread/847615?answerId=906868022#906868022, /profile/Alihan1'] its embedded XPC service before the service sends its first message [/quote] Hmmmm, this question seems backwards to me. An XPC service is launched in response to an XPC message on its named endpoint. So are you worried about the service sending its reply to that message? Or about the service talking to some other XPC service while processing that first message? The way you’ve phrased this question is very reminiscent of this thread, where the developer was trying to sandbox a child process. And my advice for those folks was to lean in to the new es_new_descendants_client feature. Share and Enjoy — Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = eskimo + 1 + @ + apple.com
Replies
Boosts
Views
Activity
1w
-paymentQueue:updatedTransactions: called continuously every time app is in foreground
-(void)paymentQueue:(SKPaymentQueue*)queue updatedTransactions:(NSArray*)transactions In the sandbox environment this is called continuously every time my enters the foreground. I call -finishTransaction on approximately 22 transactions. Confirmed by: NSUInteger finishCount = 0; NSUInteger transactionCount = transactions.count; for (SKPaymentTransaction *aTransaction in transactions) { // Check state..if purchased or restored.. [[SKPaymentQueue defaultQueue]finishTransaction:aTransaction]; finishCount++; // Post notification telling everyone here! } NSLog(@Finsihed %lu of %lu,finishCount,transactionCount); The log at the bottom says - finished 22 of 22 transactions. But every time the app enters the foreground the -paymentQueue:updatedTransactions: is called again with another batch of transactions. How Over and over again. Not sure how this is possible but the transactions seem to never clear from the queue. I hope this may be limited to the sandboxed environment. In this loop after finish
Replies
0
Boosts
0
Views
231
Activity
1w
Reply to Sandboxed SMAppService LaunchDaemon: supported identity and persistent storage?
So, before we get to the technical question here, there’s the concern that Etresoft raised. If the goal of sandboxing your daemon is so that you can ship this product on the Mac App Store, it’s not at all clear as to whether that’ll work. While SMAppService is capable of installing a sandboxed daemon from a sandboxed app [1], App Review has traditionally taken a dim view of Mac App Store apps that try to escalate privileges. OTOH, they do allow code to run as root in at least one case, namely Network Extension providers that are packaged as a system extension [2]. I recommend that you talk to App Review to see if they have any guidance here. Coming back to the technical aspects of this, I don’t think it’s feasible to change user ID in a sandboxed daemon. The App Sandbox was designed for apps, and apps can’t change user ID. There’s precedent for enabling App Sandbox in a daemon [3] but those don’t change user ID. Critically, the App Sandbox has ver
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
1w
400 error is returned for the request sent to the External Purchase Server API.
Hello. I am having trouble because when I send a request to the External Purchase Server API from my own server, I receive a 400 error, but the response does not specify a reason. ・Sent data (some information is masked with ) marketplaceToken received from the client: eyJhcHBBcHBsZUlkIjo2NzU5MTg2MjcyLCJidW5kbGVJZCI6ImNvbS5IYWJiaXQuQW5hRG9zLlBh**************************************************************************************************************************************************************************************************************************CJ0b2tlblR5cGUiOiJDT1JFX1RFQ0hOT0xPR1kifQ== The content of the Bearer Token used when performing a cancellation operation for this payment transaction: {iss:a5******---****-3c08,iat:1790134367,exp:1790135567,aud:appstoreconnect-v1,bid:com...Pal} The JWT actually sent: eyJ0eXAiOiJKV1QiLCJhbGciOiJFUzI1NiIsImtpZCI6Ikg5N1dOOTRLNjYifQ.eyJpc3MiOiJhNTU******************************************************************************************************************
Replies
0
Boosts
0
Views
57
Activity
2w
ExternalPurchaseCustomLink.isEligible always returns false in Japan Sandbox
ExternalPurchaseCustomLink.isEligible always returns false although the documented Japan requirements are satisfied. Environment: iPhone, iOS 26.7 Bundle ID: com.audio.yoho.ios Storefront: JPN (143462) Japan Sandbox account canMakePayments: true AppTransaction: Sandbox, verified Signed entitlement: com.apple.developer.storekit.custom-purchase-link.allowed-regions = [jp] ExternalPurchase.canPresent also returns false. Has anyone successfully tested this API in a development-signed Sandbox build? Feedback Assistant: ExternalPurchaseCustomLink.isEligible always returns false although the documented Japan requirements are satisfied. Environment: iPhone, iOS 26.7 Bundle ID: com.audio.yoho.ios Storefront: JPN (143462) Japan Sandbox account canMakePayments: true AppTransaction: Sandbox, verified Signed entitlement: com.apple.developer.storekit.custom-purchase-link.allowed-regions = [jp] ExternalPurchase.canPresent also returns false. Has anyone successfully tested this AP
Replies
0
Boosts
0
Views
291
Activity
2w
Reply to Security Concern : Clarification on iOS App Switcher Snapshot Storage and User Accessibility
1.Where exactly are these App Switcher preview screenshots stored on the device filesystem? I'm not sure, as I've never specifically looked for them. 2.Can these App Switcher snapshots be accessed on a jailbroken iOS device? Yes, that's very likely. 3.Are these snapshots stored inside the application container No. or in a system-managed location outside the app sandbox? Yes. Can any Third party application or tool can access this screenshots in iOS device? Ignoring jail broken device, no. 5.Is there any Apple-recommended API, entitlement, or platform-supported mechanism on iOS to prevent screenshots in iOS Sure. SwiftUI has the privacySensitive(_:) view modifier, which basically handles this automatically. UIKit apps typically handled this using a different view to hide their actual view, triggered by either resignation or backgrounding. __ Kevin Elliott DTS Engineer, CoreOS/Hardware
Topic: UI Frameworks SubTopic: General Tags:
Replies
Boosts
Views
Activity
2w
Reply to Can a Mac App Store app open a bundled, signed MCPB for installation in Claude Desktop?
Thanks, that’s helpful regarding replies vs comments and Meet with Apple. Just to clarify, my concern is not a generic “will App Review like my app?” question. I’m trying to verify one specific distribution boundary before finalizing the onboarding flow: whether a sandboxed Mac App Store app may include its own pre-signed .mcpb Desktop Extension as a bundled resource and, after an explicit user action, open that resource using standard macOS APIs so Claude Desktop presents its own native installation and consent UI. The app would not silently install anything, modify Claude’s configuration, automate its UI, download executable code, or bypass user consent. I’ve already submitted the same narrow question to Apple Developer Support. I’m mainly trying to determine whether this pattern is something Apple has previously accepted or whether there is a specific guideline that would prohibit it.
Replies
Boosts
Views
Activity
2w
Reply to Sandboxed SMAppService LaunchDaemon: supported identity and persistent storage?
We need a sandboxed Mac App Store app to install its bundled, sandboxed SMAppService LaunchDaemon through one in-app action and the required native approval. The LAN listener must be unprivileged and remain available after logout and at boot. Can't do that in the Mac App Store. LaunchDaemons run as root.
Topic: App & System Services SubTopic: Core OS Tags:
Replies
Boosts
Views
Activity
2w
Reply to CTFontManagerCreateFontRequestRunLoopSource does not receive events in macOS 27
It will be a few days before I can test that on 13-26 and remove the XPC service. An unsandboxed launch agent contained in a sandboxed app does seem to work, with XPC, on versions 13, 15, and 27. Haven't tested the other versions. I'm unaware of any specific change over the past two years to get sandboxed XPC working to this extent. Obviously this isn't for the Mac App Store. But it will simplify things. Ironically enough, now I can get rid of a bunch of XPC.
Topic: App & System Services SubTopic: General Tags:
Replies
Boosts
Views
Activity
2w