Posts under App & System Services topic

Post

Replies

Boosts

Views

Activity

New features for APNs token authentication now available
Team-scoped keys introduce the ability to restrict your token authentication keys to either development or production environments. Topic-specific keys in addition to environment isolation allow you to associate each key with a specific Bundle ID streamlining key management. For detailed instructions on accessing these features, read our updated documentation on establishing a token-based connection to APNs.
0
0
4k
Feb ’25
Meet State Reporting and the new MetricKit
Hello developers! Thank you for your dedication to creating apps with great performance. We’re excited to kick off another year of partnering with you on improving power and performance in your apps. At WWDC26, check out the following new things in the latest platform SDKs and Xcode 27 beta for performance. You can also join us online for a Power and Performance Group Lab on Tuesday, June 9 at 11 AM Pacific. Meet State Reporting and the new MetricKit State reporting: The new StateReporting framework lets your application express its state to downstream tools like Instruments and MetricKit. Make your telemetry and traces much more useful by adopting this simple API. MetricKit: In the 27 releases, the Swift-first MetricManager API replaces the MXMetricManager API. Combined with State Reporting, the new MetricKit provides more granular metrics to isolate performance problems faster. It also provides a more expressive API that is great to use in Swift, with improved Swift concurrency and Codable support. With this year’s releases, the MXMetricManager API is considered legacy. ▶️ To learn more, watch Meet the new MetricKit. Discover new features in Xcode organizer Metric goals: Xcode organizer now provides a goal metric for Battery Usage, Disk Writes, Hang Rate, Hitches, Memory, and Storage metrics, allowing you to prioritize performance engineering across more areas. Generate recommendations: Quickly resolve the highest impact performance issues in your app by using Generate Recommendations for Crash, Energy, Disk Write, Hang and Launch diagnostics. Insights overview: The new insights overview in Xcode organizer summarizes high-impact performance regressions for metrics and diagnostic reports, helping you plan and prioritize performance engineering work. Storage metrics: Storage metrics are now available in Xcode organizer, allowing you to monitor your app's Documents & Data and App Size across releases and catch regressions in cache usage and bundle size. Hitches metric: The new Hitches metric replaces the Scrolling metric in the organizer and now displays hitches for all animations in your app, giving you a comprehensive view of animation performance. ▶️ To learn more about other advancements in Xcode, watch What’s new in Xcode 27. Improve app responsiveness with Instruments Foundation Models: The Foundation Models instrument is redesigned with a tree view that lets you drill into individual requests, inspecting tool call arguments and results, inference prompts and responses, and token statistics. Use it to understand caching behavior, measure latency, and optimize throughput. System Trace: System calls, VM faults, and thread states are now unified into a single plot, with a new blending algorithm that stays readable even at high density. Once you spot something worth investigating, left/right key navigation lets you follow a thread's activity step by step, and the inspector provides quick actions like pinning the thread that made another thread runnable. System Trace now also draws thread priority and QoS over time, making it easier to identify priority inversions and unexpected QoS degradations that affect responsiveness. Swift Concurrency: New Main Actor and Global Concurrent Executor tracks let you visualize running tasks and executor queue depth over time, making it easier to spot task scheduling delays and actor contention. Tasks are now grouped into collections for faster navigation. Swift Tasks, Actors, and Executors instruments can now surface Call Trees, Flame Graphs, and Top Functions scoped to each entity — so you can pinpoint exactly where concurrency overhead lives. Top Functions: Helper functions and runtime internals can be expensive but hard to spot in a standard call tree. The new aggregation mode in Top Functions surfaces any function's total execution time across the entire call stack, making it easy to identify and prioritize hidden hotspots. Run Comparison: Compare call tree data across builds to identify regressions and performance wins. Results can be explored as an outline, flame graph, or top functions — choose whichever view best fits your workflow. ▶️ To learn more about profiling your app with Instruments, watch “Profile, fix, and verify: Improve app responsiveness with Instruments” ▶️ To learn about Foundation Models optimization, watch “Debug and profile agentic app experiences with Instruments”. If you have any questions about using State Reporting or the new MetricKit, create a post on the forums. For help creating a post, see Tips on writing a forum posts.
0
0
1.7k
Jun ’26
TestFlight: StoreKit 1 and 2 return USD prices, but purchase sheet shows JPY
I'm investigating a price/currency mismatch in a TestFlight app. Environment: iPhone 15, iOS 26.6.2 App version 0.4.2 (Build 47), distributed through TestFlight Consumable product ID: line_stamp_8pack_1980 Diagnostic comparison: October 5, 2026, at 11:22:47 JST (UTC+09:00) For the same product, all three product lookup paths returned price 11.99, currency USD, and display price $11.99: StoreKit 1: SKProductsRequest / SKProduct StoreKit 2: Product.products(for:) expo-iap: fetchProducts The direct StoreKit calls were made through native Swift diagnostics in the app. All three lookups succeeded without errors. StoreKit 2 reported storefront country USA and ID 143462 before and after its lookup. expo-iap also reported USA before and after its lookup. StoreKit 1's storefront was unavailable before its request. Afterward, it reported USA, with storefront identifier "143462-9,29". Our diagnostic initially labeled this as a storefront change, but an unavailable-to-available result does not establish an actual country change. During the same testing session, Apple's purchase confirmation sheet for this product displayed ¥1,980 and stated that the purchase was for testing only. I canceled the sheet without completing the purchase. The Media & Purchases account's country/region is Japan. App Store Connect pricing for this product is ¥1,980 in Japan and $11.99 in the United States. What could cause the product lookup APIs to return the US storefront price while the purchase confirmation sheet displays the Japanese price? What additional diagnostics should I collect to identify the cause and obtain a product price consistent with the purchase sheet? Thank you.
0
0
221
4h
Custom Installer Plugin (x86_64 bundle) is not loaded on macOS 26A428 / 25G229 / 24H23, causing an installer GUI pane to be skipped
Summary A third-party PKG installer that ships a custom Installer Plugin no longer displays one of its selection panes. The plugin bundle appears not to be loaded, so the pane that it provides is silently skipped and the user cannot choose the intended installation option. This behavior started with recent macOS releases and did not occur on the immediately preceding versions, so it looks like a regression. Environment Machine: MacBook Pro 14-inch (M3) Affected builds: macOS 27.0 (26A428) macOS 26.7 (25G229) macOS 15.8 (24H23) Not affected: macOS 26.6 and earlier macOS 15.7 and earlier Reproducibility: every time Plugin binary: Mach-O 64-bit bundle, x86_64 only (no arm64 slice) Steps to Reproduce Download the Epson iProjection Ver.4.04 installer from the vendor support site: https://support.epson.net/setupnavi/?LG2=EN&OSC=MI&PINF=vpapp&MKN=EB-770Fi Mount the downloaded disk image and run the PKG installer. Step through the installer GUI and observe the pane transitions. Expected Result The installer GUI shows the "Application type" selection pane provided by the bundled Installer Plugin. Actual Result The "Application type" pane is never shown. The installer proceeds as if the plugin did not exist, and the user cannot select the installation type. What I Checked 1. The plugin is present inside the PKG pkgutil --expand-full PKG_PATH DEST_DIR The expanded payload contains the plugin bundle and its Mach-O executable under Contents/MacOS. 2. Architecture of the plugin binary file DEST_DIR/PluginName.bundle/Contents/MacOS/PluginName Result: Mach-O 64-bit bundle x86_64. It is a single-architecture binary with no arm64 slice. 3. The plugin is actually touched at install time sudo fs_usage -w -f filesys InstallerRemotePluginService-x86 opens the plugin executable inside the installer's temporary directory (a path under /private/tmp/com.apple.installer* ). So the plugin is reached as a load target, but the pane still does not appear. 4. Code signature validation When the installer is launched directly from the mounted disk image, code signature validation fails with: Too many levels of symbolic links My working theory is that the bundle contents are turned into symbolic links when the plugin is expanded, and that this causes codesign validation to fail, so the plugin is rejected before it can register its pane. 5. Code evaluation by syspolicyd log stream --info --debug --predicate 'process == "syspolicyd"' GK package assessment, GK process assessment and GK performScan entries are present, so Gatekeeper evaluation itself is running. The following also appears: Error Domain=NSOSStatusErrorDomain Code=-67062 Unsigned code in: PST: (path: REDACTED), (team: (null)), (id: (null)), (bundle_id: (null)) The PST path is anonymized in the log, so I could not confirm that this particular assessment refers to the plugin bundle. 6. XProtect evaluation results differ between versions log stream --info --debug --predicate 'process == "syspolicyd"' On the versions where the installer works correctly, the GK Xprotect results lines explicitly include a file URL pointing at the plugin bundle inside the installer temporary directory. On the affected builds, searching the same log for the plugin bundle name returns zero matches. That suggests the bundle is not being processed as an XProtect evaluation target at all on the newer builds. Question Was there a change in how Installer Plugins are expanded or validated in these releases, in particular around symlinked bundle contents or single-architecture x86_64 plugins? Any guidance on the supported way to ship an Installer Plugin so that it is still loaded on current macOS would be appreciated.
2
0
633
7h
Can a Third-Party App Using Critical Alerts Display a Full-Screen Emergency Alert Like iOS Emergency Alerts?
We are considering developing an iPhone application for workers operating in environments where safety is critical and notifications may involve life-threatening situations. We understand that Apple's Critical Alerts feature can deliver notifications with audible alerts even when the device is muted or Focus mode is enabled. However, we would like to know whether it is possible for a third-party app using Critical Alerts to present an emergency alert directly on the screen in the foreground, similar to the way iOS displays government-issued emergency alerts such as Earthquake Early Warnings (EEW). Specifically, can a third-party application trigger a full-screen emergency alert that immediately appears over other applications, rather than relying solely on a notification banner and alert sound? If this is not possible, are there any Apple-supported mechanisms or APIs that allow life-safety applications to provide a comparable user experience for urgent emergency notifications? We would appreciate any clarification regarding the capabilities and limitations of Critical Alerts for life-safety use cases.
0
0
234
8h
WCSession.sendMessage is crashing when a reply or error handler is attached, why?
The following code should send a message from the watch to the iPhone. Unfortunately, it is crashing. I have no clue why. if WCSession.isSupported() { let session = WCSession.default if ((session.activationState == .activated) && session.isReachable) { session.sendMessage(["SimpleMessages":["start"]], replyHandler:{reply in _ = 0 }, errorHandler:nil) } } If the reply handler is set to nil, the code does not crash. Anyway, in both cases the message is correctly sent from the watch to the phone. The code itself is run on the main thread (verified). I am running watchOS 26.6 and iOS 27. Here is the crash : Stack trace
0
0
62
9h
iOS 27 simulator never shows the AlarmKit permission prompt
Spent a good while debugging my own alarm code before working out the problem wasn't mine, so here it is in case someone's about to do the same thing. iOS 27 simulator, erased, clean install. requestAuthorization() comes back .denied and you never get a permission dialog at all. I had XCUITest sitting there watching SpringBoard for an Allow button over a bunch of runs, nothing. You can grant it manually in Settings and then authorizationState says .authorized, so the permission itself works, it's just the prompt that doesn't happen. On my actual phone (13, same 27.0) everything's normal, it schedules and rings and the alert comes up with snooze and stop on it. Then I went back to a 26.3 sim to compare and that one's worse here. SpringBoard keeps crashing, every few minutes, same thing each time: -[TLAlertQueuePlayerController _prepareAudioEnvironmentForStateDescriptor:isForMusicPlayback:] Unrecognised selector, SIGABRT, while it's trying to play the alert tone. It did that on a device I'd just erased with my app not even installed yet. Has anyone got the AlarmKit prompt to show up on 27 at all? Flag, particular device, entitlement, something in the plist I'm missing? And if you did grant it by hand there, do alarms actually fire afterwards on the sim? I never got far enough to find out, I just moved to the phone. Also curious whether anyone else sees that ToneLibrary crash on 26.3 under macOS 27. The AlarmKit wrapper I was poking at when I hit this is a free MIT gist, auth handling and deterministic alarm ids and the cancel-then-schedule ordering that got me earlier in the week: https://gist.github.com/yakubmurcek/61d8e3a60eb81e2c1f785010b4aa46de
0
0
74
12h
Dual-stack UDP socket bound to port 0 can get a port already in use on 127.0.0.1 (FB25058707)
I filed FB25058707 and wanted to make sure it reaches the right people, because it causes silent datagram loss that's hard to trace. On macOS, when a dual-stack UDP socket (AF_INET6 with IPV6_V6ONLY=0) binds [::]:0, the kernel sometimes gives it a port that an AF_INET socket already has bound to 127.0.0.1. Datagrams sent to 127.0.0.1 on that port then go to the AF_INET socket, so the dual-stack socket never receives them. An explicit bind of the same socket to that port fails with EADDRINUSE; only port-0 assignment hands it out. This program binds 1000 AF_INET sockets to 127.0.0.1:0, then binds dual-stack sockets to [::]:0 and checks where a datagram to 127.0.0.1:port lands whenever the port is already held. It's loopback only and runs in a few seconds: /* * A dual-stack UDP socket (AF_INET6, IPV6_V6ONLY=0) bound to [::]:0 can be * assigned a port already bound by an AF_INET socket on 127.0.0.1. Datagrams * to 127.0.0.1:port then reach the AF_INET socket, not the dual-stack one. * Loopback only. Build: cc -O2 -o dualstack_port0 dualstack_port0.c */ #include <arpa/inet.h> #include <errno.h> #include <netinet/in.h> #include <stdio.h> #include <stdlib.h> #include <string.h> #include <sys/resource.h> #include <sys/socket.h> #include <sys/time.h> #include <unistd.h> #define HELD 1000 #define TRIALS 2000 static int held[65536]; static void die(const char *what) { perror(what); exit(1); } static int port_of(int s) { struct sockaddr_storage ss; socklen_t len = sizeof(ss); if (getsockname(s, (struct sockaddr *)&ss, &len) != 0) die("getsockname"); if (ss.ss_family == AF_INET) return ntohs(((struct sockaddr_in *)&ss)->sin_port); return ntohs(((struct sockaddr_in6 *)&ss)->sin6_port); } static int bind_v4(in_addr_t addr) { int s = socket(AF_INET, SOCK_DGRAM, 0); if (s < 0) die("socket AF_INET"); struct sockaddr_in sin = { .sin_len = sizeof(sin), .sin_family = AF_INET, .sin_addr.s_addr = addr }; if (bind(s, (struct sockaddr *)&sin, sizeof(sin)) != 0) die("bind AF_INET"); return s; } static int bind_dual(void) { int s = socket(AF_INET6, SOCK_DGRAM, 0), off = 0; if (s < 0) die("socket AF_INET6"); if (setsockopt(s, IPPROTO_IPV6, IPV6_V6ONLY, &off, sizeof(off)) != 0) die("IPV6_V6ONLY"); struct sockaddr_in6 sin6 = { .sin6_len = sizeof(sin6), .sin6_family = AF_INET6, .sin6_addr = in6addr_any }; if (bind(s, (struct sockaddr *)&sin6, sizeof(sin6)) != 0) die("bind AF_INET6"); return s; } /* Returns 1 if s receives token within 100ms, skipping other datagrams. */ static int got(int s, const char *token) { struct timeval tv = { .tv_sec = 0, .tv_usec = 100000 }; if (setsockopt(s, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv)) != 0) die("SO_RCVTIMEO"); char buf[64]; for (;;) { ssize_t n = recv(s, buf, sizeof(buf) - 1, 0); if (n < 0) { if (errno == EAGAIN || errno == EWOULDBLOCK) return 0; die("recv"); } buf[n] = 0; if (strcmp(buf, token) == 0) return 1; } } int main(void) { struct rlimit rl; if (getrlimit(RLIMIT_NOFILE, &rl) != 0) die("getrlimit"); rl.rlim_cur = rl.rlim_max < 4096 ? rl.rlim_max : 4096; if (setrlimit(RLIMIT_NOFILE, &rl) != 0) die("setrlimit"); memset(held, -1, sizeof(held)); for (int i = 0; i < HELD;) { int s = bind_v4(htonl(INADDR_LOOPBACK)), p = port_of(s); if (held[p] >= 0) { close(s); continue; } held[p] = s; i++; } int sender = bind_v4(htonl(INADDR_LOOPBACK)); for (int dual = 1; dual >= 0; dual--) { int collisions = 0, to_held = 0, to_wild = 0; for (int i = 0; i < TRIALS; i++) { int w = dual ? bind_dual() : bind_v4(htonl(INADDR_ANY)), p = port_of(w); if (held[p] >= 0) { collisions++; char token[32]; snprintf(token, sizeof(token), "%d-%d", dual, i); struct sockaddr_in to = { .sin_len = sizeof(to), .sin_family = AF_INET, .sin_port = htons(p), .sin_addr.s_addr = htonl(INADDR_LOOPBACK) }; if (sendto(sender, token, strlen(token), 0, (struct sockaddr *)&to, sizeof(to)) < 0) die("sendto"); to_held += got(held[p], token); to_wild += got(w, token); } close(w); } printf("%s: %d/%d wildcard binds got a port held by a 127.0.0.1 socket; the probe reached that socket %d times, the wildcard socket %d times\n", dual ? "AF_INET6 V6ONLY=0 [::]:0" : "AF_INET 0.0.0.0:0 ", collisions, TRIALS, to_held, to_wild); } return 0; } On macOS 27.0 (26A428): AF_INET6 V6ONLY=0 [::]:0: 122/2000 wildcard binds got a port held by a 127.0.0.1 socket; the probe reached that socket 122 times, the wildcard socket 0 times AF_INET 0.0.0.0:0 : 0/2000 wildcard binds got a port held by a 127.0.0.1 socket; the probe reached that socket 0 times, the wildcard socket 0 times macOS 15.8.1 x86_64 gives the same pattern, and a Go version of the test reproduces on 15.7.9 and 26.6.2 as well. FreeBSD 15.1 gives 0/2000 with a dual-stack socket. From the public XNU source (xnu-12377.121.6), in6_pcbsetport checks candidate ports with in6_pcblookup_local, which skips PCBs without INP_IPV6, while in6_pcbbind does an IPv4 PCB lookup for dual-stack wildcard binds. That would explain why an explicit bind is refused but port 0 isn't. This is the cause of the long-standing Go issue golang/go#67226, since Go's net.ListenUDP("udp", 0.0.0.0:0) creates exactly this socket, and of intermittent failures in QUIC client tests. Using an AF_INET socket for IPv4-only traffic avoids it, but there's no workaround for a socket that needs both families on one port.
0
0
74
12h
Title: Security-scoped folder bookmarks after rename or Trash: APFS vs exFAT/FAT32
I’m developing a sandboxed macOS app that needs persistent, read-only access to a user-selected folder. We are observing different behaviour between APFS and FAT32/exFAT after renaming the folder or moving it to Trash. The main problem is that the app can still track the folder while running, but cannot reliably restore the connection or identify its location after relaunch. Environment macOS 27.0.1 (26A434) Xcode 27.1 (27A9269) App Sandbox and user-selected file access enabled Folder selection through SwiftUI fileImporter Bookmark creation: .withSecurityScope and .securityScopeAllowOnlyReadAccess Bookmark resolution: .withSecurityScope The selected items are ordinary folders, not volume roots. Filesystem comparison APFS: the tested workflows appear to work as expected, including restoration after relaunch. exFAT: we have reproduced both bookmark renewal failure after a rename and loss of the “in Trash” classification after relaunch. FAT32: we have observed automatic bookmark renewal failures after a rename. The detailed debugger trace and Trash reproduction below were collected specifically on exFAT. Rename reproduction Select a folder through the system picker. Create and persist a read-only security-scoped bookmark. Resolve the bookmark and start accessing the resolved URL. Retain that URL and keep its security scope active throughout monitoring. Rename the folder in Finder while the app remains running. Attempt to create an updated bookmark for the same folder. The monitor retains an O_EVTONLY directory descriptor. After the rename, F_GETPATH returns the correct new pathname, and runtime identity checks still match the monitored folder. However, creating a bookmark using a URL reconstructed from that new pathname fails. Calling startAccessingSecurityScopedResource() on the reconstructed URL returns false, while the original resolved URL’s scope remains active. The bookmark creation call uses: url.bookmarkData(options: [.withSecurityScope, .securityScopeAllowOnlyReadAccess], includingResourceValuesForKeys: nil, relativeTo: nil) Exact failure measured on exFAT LLDB shows that Foundation’s internal open(): Receives the correct new pathname. Uses flags 0, meaning O_RDONLY. Immediately returns -1. Sets errno to 1, EPERM, read immediately on the same thread. The correlated Foundation error reports: NSCocoaErrorDomain Code 256 Could not open() the item: [1: Operation not permitted] This is a failed read-only open during bookmark creation. We have not established which policy causes the EPERM. A log stream filtered for com.apple.sandbox.reporting / violation produced no report during reproduction. We understand that this does not exclude sandbox involvement. We also tested a native CFURL file reference retained from before the rename. It continued to follow the folder and match its identity, but security-scoped bookmark creation from that reference also failed. Reselection works, but requires user intervention Selecting the same renamed folder again through fileImporter allows creation of a new bookmark. That bookmark resolves, is not stale, and restores access after relaunch. Without reselection before quitting, the previously saved bookmark does not restore access to the renamed folder on the next launch. The app reports it as unavailable. Separate Trash reproduction on exFAT Move the monitored folder to Trash using Finder while the app is running. The app correctly identifies the folder as being in Trash. Quit the app, leaving the folder in Trash. Relaunch: the app reports the folder as unavailable. The folder remains in Trash on the same exFAT volume. It has not been restored or permanently deleted. We also encountered failures when inspecting the Trash relationship using FileManager.getRelationship(_:of:in:toItemAt:) with .trashDirectory. We have not established whether these observations share the cause of the rename failure. Questions What is the supported public-API approach to preserve security-scoped folder access across an external rename on exFAT/FAT32, including after relaunch? What should bookmark resolution return for a folder moved to Trash, and how should a sandboxed app distinguish that condition from an unavailable resource after relaunch? Are these expected filesystem limitations, problems in our API usage, or behaviours that should be reported as macOS bugs? What additional diagnostics would help distinguish them? Ideally, the solution would preserve the original folder authorization without requiring repeated reselection or access to the parent directory or entire volume. I have read Accessing files from the macOS App Sandbox. I also found this discussion of bookmark failures involving exFAT, but it concerns volume roots and an earlier macOS release, so I’m not assuming it explains our case.
3
0
116
13h
Apple Watch Ultra 2: headingAccuracy near 89° even with correct heading; intermittent 180° reversal
Apple Watch Ultra 2, watchOS 27.0, Xcode 27. I use CLLocationManager.startUpdatingHeading(), headingFilter=1 and CLHeading.magneticHeading directly, with no offset or GPS course. During surfing, my app and Apple Compass both showed an apparent error of about 180 degrees. The iPhone was not nearby or connected. Later, outside water, readings returned to normal. An analog compass on the opposite arm differed by about 30 degrees initially, then agreed. All saved Int(headingAccuracy) values were 89; it still displays 89 while the heading is correct. Raw fractional values were not saved. Is this an expected or sentinel value on watchOS? What calibration and diagnostics are recommended for the intermittent reversal? The app also uses an underwater-depth extended runtime session; its errors have not been linked to the heading issue.
0
0
81
14h
Supported pre-initializer capture and failure enforcement for macOS guests
SANITISED SUPPORTED MACOS CAPTURE API INQUIRY REVIEW CORRECTIONS APPLIED — DRAFT, NOT SENT Question ID: MACOS-PROTECTED-CAPTURE-PROVIDER-20261004-02 Purpose: identify supported public capabilities; no project acceptance or native-execution approval is requested. Is there a supported public API combination on Apple silicon for capturing unchanged Apple-signed clang, ld and codesign inside a macOS guest after authenticated loader bootstrap but before any initializer, resolver or other target code? Only individually authenticated and explicitly enumerated loader-bootstrap operations may execute before capture; no blanket system-library exemption is assumed. The required observer/enforcer must remain outside tested guest-root authority. Include compromise of the submitting host's administrator. Observation, enforcement, state, custody, revocation and expected admission pins must not rely solely on controls that administrator can forge, replace or recover; remote signing or storage of its assertions is insufficient. The barrier must bind the exact process and guest generation, stop all target threads and byte/mapping writers, and capture complete actual loaded images, shared-cache membership, mappings, segment/private relocated bytes and backing identities coherently. Absent, crashed or disconnected observers, failed captures and missing verified release must keep execution blocked or terminate it before forbidden instructions. Release must be evidence-verified, same-incarnation and one-use. Guest termination must integrate with closed admission and generation fencing against saved-state resume, clone and replay. Our previously supplied context is macOS 26.6.2/SDK 26.5, observed but unattested. We have not run native qualification. Please state required host/guest versions explicitly; an upgrade is not assumed. Current public component documentation establishes: ES_EVENT_TYPE_AUTH_EXEC is an image-execution authorization event. es_set_deadline_miss_mode with ES_DEADLINE_MISS_MODE_FAIL_CLOSED (setter introduced in macOS 27) covers missed authorization deadlines and full-queue drops. Does this also cover client crash, deletion, disconnect or unsubscription, and could any such combination enforce the required post-loader barrier? VZVirtualMachine.pause provides VM lifecycle pausing; stop provides destructive stop with completion/error reporting. VZGuestMemoryMapping (macOS 27) exposes DRAM ranges through custom Virtio devices; the overview describes Linux guests. Is supported macOS guest use available for this purpose, and what coherent-capture/other-writer guarantees exist? Please identify the exact supported symbols and deployment configuration, documented pre-entry ordering and failure guarantees, supported macOS guest applicability, and required entitlements/signing policy. Also state whether protection weakening, target re-signing or changed system components would be required. Such requirements are compatibility limitations, not permission to perform those changes. If the full capability is unsupported, identify the specific missing public interface or guarantee rather than proposing an unsupported workaround. Public references: https://developer.apple.com/documentation/endpointsecurity/es_event_type_auth_exec https://developer.apple.com/documentation/endpointsecurity/es_set_deadline_miss_mode(::) https://developer.apple.com/documentation/endpointsecurity/es_deadline_miss_mode_fail_closed https://developer.apple.com/documentation/virtualization/vzvirtualmachine/pause() https://developer.apple.com/documentation/virtualization/vzvirtualmachine/stop(completionhandler:) https://developer.apple.com/documentation/virtualization/vzguestmemorymapping https://developer.apple.com/videos/play/wwdc2026/224/ Only this sanitised text and its public references are intended for relay. No private artifacts, personal/host identifiers, credentials or logs are needed. A provider reply is capability evidence; implementation, actual bindings, independent qualification, Founder acceptance and activation remain separate.
0
0
77
19h
TestFlight: StoreKit 2 returns no consumables despite active agreements; HTTP 200 and empty product response
Hello, We are troubleshooting product discovery for three consumable In-App Purchases in our first iOS game, ION RUSH. All three remain unavailable in TestFlight. Environment and result: Physical iPhone 13, iOS 27.0.1 (24A446). App version 1.0 (80), installed through TestFlight. Direct native StoreKit 2; no RevenueCat or other purchase SDK. Product.products(for:) returns zero products before application filtering, without throwing an error. Earlier independent development-build diagnostics also returned zero products for batch and individual StoreKit 2 requests; SKProductsRequest reported all three identifiers as invalid. Checks completed: Product IDs exactly match App Store Connect: nova_pack_5, nova_pack_15, nova_pack_40. The explicit bundle identifier matches the app record and code; In-App Purchase is enabled for the App ID. All three consumables show Ready for Review, have prices and localizations, and are available in all 175 configured territories, including the US. Developer membership, Paid Apps Agreement, bank account and tax forms are active. The Account Holder checked the Developer account for outstanding agreement signatures; none were visible. The Developer Program agreement was accepted September 29. Tax forms were submitted October 3 and now show Active. The financial setup was only recently completed, so delayed activation remains a possibility. The release scheme has no local StoreKit Configuration override. TestFlight reinstallation, device restart and repeated product refreshes did not restore the products. A re-export of the exact build 80 archive with the original App Store Connect signing settings selected an explicit App Store profile with beta-reports-active=true and get-task-allow=false. This checks the signing configuration; the original uploaded IPA was not available for direct inspection. Selected storekitd messages from October 4, 2026 (UTC+3): 09:59:22.963356 Requesting Media API product batch ["nova_pack_15", "nova_pack_40", "nova_pack_5"] 09:59:22.990339 summary for task success {transaction_duration_ms=1, response_status=200, cache_hit=true} 09:59:22.991595 Ignoring empty product response The request targets amp-api.sandbox.apple.com/v1/catalog/us/in-app-purchasables with the correct bundle and product IDs. Its account mediaType is com.apple.AppleMediaServices.accountmediatype.appstore.beta. A second request one second later produced the same HTTP status, cache flag and empty-product message. We did not capture the raw HTTP response body. Local StoreKit configuration tests work, but we understand this does not validate the live Sandbox catalog. We also understand that prior IAP review approval is not required for Sandbox testing. Questions: What additional developer-side check would distinguish incomplete account activation, product configuration or cached catalog state in this situation? Has anyone resolved this after completing agreements/banking/tax, especially when the products were created before financial activation? What exact action or elapsed time resolved it? If all TN3186 checks pass, what evidence and official escalation route should we use to request investigation of the app-to-product catalog association? Related reports: https://developer.apple.com/forums/thread/849165 (same storekitd messages, but after membership lapse/renewal; our situation differs) https://developer.apple.com/forums/thread/844545 (zero StoreKit 2 products and invalid StoreKit 1 identifiers after TN3186 checks) We can provide further redacted diagnostics and account details privately to Apple. Thank you.
0
0
64
19h
Opening Hours for Map Routing
I'm looking to access Apple Maps place metadata, particularly opening hours to route a user between 3 points. Suppose point C opens in the morning and B in the evening, I'd make sure to route the user based on which place is open at the time, eg A => C => B I understand from this thread that opening hours is not something app integrations can export. I was also checking out the batch endpoint. While its not necessary to export the data or display it inline, I'm looking for ways that my app can consume or consider this when routing between multiple places.
0
0
26
19h
CloudKit Background Export After Internet Reconnects
I’m seeing a repeatable failure to export changes in the background with an NSPersistentCloudKitContainer private database on iPhone. While offline, I create an object and save its managed object context. I then leave the app and lock the phone. After Wi‑Fi reconnects, the change remains absent from the same app on my Mac. Opening the iPhone app causes it to sync and appear on the Mac. The unplugged sequence reproduces this. When I tried the same sequence with the iPhone plugged in, background sync worked. In a sysdiagnose from an unplugged occurrence: 16:44:21: The context saved the new object. 16:44:21: dasd queued the CloudKit export but reported networkPathAvailability = 0. 16:44:27: iOS suspended the app. 16:48:21: Wi‑Fi reported a satisfied path. Through 16:54:42: No subsequent export attempt appeared in the logs. Opening the iPhone app caused the change to appear on the Mac. In the same offline-to-online routine, a reminder created in Apple Reminders appears on my Mac without reopening Reminders on the iPhone; my app’s new object does not appear until I reopen my app on the iPhone. Is a queued NSPersistentCloudKitContainer export expected to run after connectivity returns while the app remains suspended and unplugged? If so, what should I check to learn why it did not run here? Or does Reminders receive background scheduling priority that third-party apps cannot use?
1
0
95
20h
Supported completeness and lifecycle guarantees for es_new_descendants_client
Hello Apple Developer Technical Support, I am evaluating es_new_descendants_client for a local command runner that must report success only after its workload and every process descended from that workload have exited. If observation is incomplete or ambiguous, the runner must report failure. This is a design inquiry, not a report of a reproduced operating-system defect; no entitled prototype has been tested. The proposed observer would create its client and subscribe to lifecycle notifications before launching any workload. It would maintain a registry using process-lifetime identities, add processes on creation and remove them on exit. An unmatched event, missing required field, detected loss or observer failure would invalidate the run. It would consider closure only after all registered workload processes had exited. We have not established that these rules are sufficient. Could you clarify which of the following properties are supported API guarantees, and identify any that applications must not rely on? A documented reference or an explicit statement that a guarantee is unavailable would both help. Please identify applicable macOS/SDK versions and any known version-dependent limitations. 1. Membership and creation-event coverage Does the observed subtree retain a process and all of its future descendants after its original parent exits, it is reparented, it double-forks, or it changes process group/session with setpgid or setsid? Could a process remain observable for exit while creation events for its children become invisible? For a workload launched after successful subscription, does every successful process-creation path—including fork, vfork and posix_spawn—produce a lifecycle event sufficient to register the new process before closure can be declared? Which event and identity fields should be used for each path, including a child that exits without a successful exec? Does the calling observer receive the necessary event for its own initial workload launch? 2. Ordering and the meaning of exit Is there a supported per-client ordering guarantee that every child-creation event from a process is delivered before that process's exit notification, including concurrent creation and exit? Can the child's events arrive before the event that introduces that child? Please distinguish kernel enqueue order, handler delivery order and any processing order the application must impose. At what lifecycle boundary is ES_EVENT_TYPE_NOTIFY_EXIT generated? Does it establish that the identified process can no longer execute or initiate writes, or can relevant activity continue after the notification? We would not equate process exit with filesystem durability or completion of work already delegated to other processes. 3. Muting and other visibility filters Does a newly created descendants client have default process, path or target-path mutes that can suppress fork/exit notifications? What supported sequence of configuration and inspection calls establishes complete lifecycle visibility before launch, including mute inversion and executable-path changes? Apart from subscription and muting, are there policy, security, rate-limit or client-type exclusions that can suppress those events? Which suppressed events, if any, are intentionally absent from the sequence counter rather than reported as drops? 4. Sequence numbers and loss detection The global_seq_num documentation requires message version greater than 4. Is that field guaranteed for descendants-client lifecycle messages? Do notifications concerning the calling observer and its descendants use the same per-client sequence? How can a client establish a valid initial baseline and detect loss before its first received message? Is every dropped subscribed, unmuted lifecycle event reflected in the next delivered sequence number? What counter reset, wraparound or client-recreation rules must be handled? Would the proposed registry rule make terminal loss fail safely—for example, a lost final exit leaves a process registered—under the supported ordering and visibility semantics? Or is there a counterexample in which the registry can become empty while an unobserved descendant survives? 5. Synchronization, observer failure and delegated work Does es_sync_client provide any loss/completeness information beyond draining preceding queued messages? Its documented callbacks also run for a destroyed or null client, so we would not interpret callback arrival alone as successful completion. Is there a supported mechanism to distinguish a healthy drain from invalidation? What does “instigates” cover for this client? In particular, can it observe or attribute work executed by existing launchd/XPC services, or by unrelated processes receiving file descriptors? We would treat such work as outside a lineage-only closure claim unless it is explicitly covered or independently excluded. Does this client provide any supported protection against a same-UID workload stopping, killing or otherwise interfering with its observer, or must that isolation be supplied separately? Observer failure would invalidate the run; we are not assuming ES supplies a write barrier for evidence files. 6. Supported cleanup and deployment Is there a supported public mechanism to signal a non-child descendant by process-lifetime identity, without a PID-reuse race between observing it and sending a signal? Is there a recommended approach if the observer cannot wait on that process? We do not want to depend on private libproc functions as an application contract. Finally, is this use case eligible for com.apple.developer.endpoint-security.client in a standalone signed command-line observer, and what supported signing/provisioning or packaging requirements apply? This is a request for guidance, not an entitlement application. Our central question is whether supported APIs can establish complete descendant-process closure under these constraints. If they cannot, we would appreciate a clear statement of that limitation or a supported alternative. Thank you. Documentation consulted: es_new_descendants_client es_sync_client global_seq_num es_process_t
5
0
713
1d
Restartable Sequences. What are they?
After scouring the XNU kernel source code, I came across restartable ranges [1]. They seem to be a task-level version of the the part of Linux's restartable sequences [2] for user requested synchronization [3] (akin to MEMBARRIER_CMD_RSEQ). Because of their differences, I would like to know more about how they work and what they are used for. From what I have gathered [4], they seem to be closer to RCU [5] that waits for eviction (as opposed to completion). But the fact that they are barely mentioned anywhere (see [4]) in the XNU source code I'd be really happy if you can point me to more information about them and how they compare to rseq (or rcu). What are the XNU devs planning on doing with them? [1] osfmk/kern/restartable.c: https://github.com/apple-oss-distributions/xnu/blob/f6217f8/osfmk/kern/restartable.c [2] https://criu.org/Restartable_Sequences [3] as opposed to (what I think is what makes rseq really cool) automatic eviction on preemption/CPU migration [4] there seems to be very little information online (including this forum) and the only places inside the XNU kernel source trees that aren't tests are in osfmk/kern/{thread,thread,sched_prim}.{c,h}, which doesn't really give much more information. [5] Read-Copy-Update: https://www.kernel.org/doc/html/latest/RCU/whatisRCU.html
2
0
415
1d
Empty Storekit Catalog Response
Hello all, I'm posting here today in hopes the internet can help me find a solution for an issue I'm having with integrating with subscriptions created in App Store Connect. I'm receiving no products back from StoreKit 2 for my list of product IDs. Things I've verified so far: No errors are coming from StoreKit The product IDs I'm requesting match the configured product IDs in the subscriptions The provisioning profile matches the bundle ID of the built app. The provisioning profile includes the in-app purchases capability. All subscriptions are priced, include localization, have an availability region set, and include a tax category. The subscriptions have been set for a week. Well over the typical one hour metadata update window. My banking, tax info, and paid apps agreement are up to date and active. I'm signed out of Media & Purchases and signed into a sandbox account under developer mode on the test device. The region of the sandbox account matches the region availability of the subscriptions. Under Signing & Capabilities in Xcode, my team matches the team the app is created under in App Store Connect, In-App Purchase is included, and we are signing with my team's certificate. The app under test is a production release build installed via Test Flight. Logging the StoreKit environment shows that it's in the sandbox and matches the region configured for the sandbox user and subscriptions Device: iPhone 14 OS: iOS 26.5.2 Thanks in advanced for any help and insight you may have.
0
0
264
1d
CarPlay Video entitlement pending for 15 days — is there an escalation path?
We submitted a request for the CarPlay Video entitlement (com.apple.developer.carplay-video) on September 15, 2026, and have not received an approval, rejection, or request for additional information after 15 days. We have already followed up through the original entitlement email thread and contacted Apple Developer Support several times. Across these exchanges, we have provided the same core information at least four times, including the entitlement Case-ID, submission date, business need, and confirmation email. However, several replies have simply asked us to provide the same information again. Developer Support has also confirmed that CarPlay entitlement requests are handled by a different team and that they do not have a direct contact or support channel for that reviewing team. At this point, is there any escalation path for a CarPlay Video entitlement request that has been pending without an update? Or is waiting several weeks currently normal for these requests? Any guidance from an Apple engineer or developers who have recently gone through the CarPlay Video entitlement process would be greatly appreciated. Thank you
1
0
83
1d
StoreKit 2 returns USD product metadata in TestFlight while the storefront is FRA/EUR
Hello, We would appreciate some guidance regarding an unexpected StoreKit currency result in a TestFlight build. Our iPhone language and region are both set to France. The Sandbox tester is also configured for France, and our subscription products have French availability and pricing configured in App Store Connect. In the TestFlight build we diagnosed, StoreKit reports the current storefront as France with EUR: storefront=FRA/143442/EUR However, all 10 subscription products are returned with USD product metadata: products=10/10 formatCurrencies=USD localeCurrencies=USD error=NONE Example: formatCurrency=USD locale=fr_US_currency_USD localeCurrency=USD display=1,99 $US price=1.99 We first observed this through Flutter's in_app_purchase integration. To determine whether the Flutter plugin was involved, we added a native StoreKit 2 diagnostic to the same TestFlight build. The native result was identical: receipt=sandboxReceipt storefront before=FRA/143442/EUR storefront after=FRA/143442/EUR products=10/10 formatCurrencies=USD localeCurrencies=USD error=NONE The issue appears specific to the TestFlight distribution. When the application is installed directly from the development computer, prices are returned in euros on the same device. We also tested with the regular Media & Purchases account signed out and a French Sandbox tester connected. Once the products loaded successfully, StoreKit still returned USD metadata. In another configuration, the application displayed the USD price while Apple's purchase sheet displayed the price in euros. We are using the price and formatting information returned directly by StoreKit. We do not want to infer the currency from the device region or perform a client-side currency conversion, because StoreKit should remain the authoritative source. Could you please help us understand: Is it expected for Storefront.current to report FRA/EUR while Product.priceFormatStyle.currencyCode, its locale currency, and Product.displayPrice use USD? Could a TestFlight or App Store Connect configuration cause product metadata to use a different currency from the current storefront? Is there another account, availability, pricing or distribution setting that we should verify? Is there a recommended way to refresh or invalidate the product metadata used by a TestFlight installation? We have already filed Feedback Assistant report FB24723329, which is currently under investigation. Thank you very much for any clarification or additional diagnostic steps you can suggest.
3
1
646
1d
In-App Purchases work in TestFlight but not during App Review
Hi everyone, I'm a new iOS developer, and my first app has been rejected twice because of In-App Purchase issues. Setup: Flutter, in_app_purchase 3.3.0, in_app_purchase_storekit 0.4.10 (StoreKit 1) One auto-renewable subscription and one non-consumable lifetime purchase Both products show "Ready for Review" in App Store Connect. Paid Apps Agreement is active. First review: The prices were visible on an iPad, but the subscription purchase failed (Guideline 2.1(b)). Second review: Neither product showed a price on an iPhone (Guideline 2.1(b)). Apple also noted missing subscription information (Guideline 3.1.2(c)). On my iPhone 15, both products load correctly and test purchases work in TestFlight using my regular Apple Account. Product IDs, pricing, availability, and localizations appear correct. My question: What could cause queryProductDetails / SKProductsRequest to return no products during App Review when everything works in TestFlight? Any suggestions would be greatly appreciated. Thanks! :)
0
0
129
1d
New features for APNs token authentication now available
Team-scoped keys introduce the ability to restrict your token authentication keys to either development or production environments. Topic-specific keys in addition to environment isolation allow you to associate each key with a specific Bundle ID streamlining key management. For detailed instructions on accessing these features, read our updated documentation on establishing a token-based connection to APNs.
Replies
0
Boosts
0
Views
4k
Activity
Feb ’25
Meet State Reporting and the new MetricKit
Hello developers! Thank you for your dedication to creating apps with great performance. We’re excited to kick off another year of partnering with you on improving power and performance in your apps. At WWDC26, check out the following new things in the latest platform SDKs and Xcode 27 beta for performance. You can also join us online for a Power and Performance Group Lab on Tuesday, June 9 at 11 AM Pacific. Meet State Reporting and the new MetricKit State reporting: The new StateReporting framework lets your application express its state to downstream tools like Instruments and MetricKit. Make your telemetry and traces much more useful by adopting this simple API. MetricKit: In the 27 releases, the Swift-first MetricManager API replaces the MXMetricManager API. Combined with State Reporting, the new MetricKit provides more granular metrics to isolate performance problems faster. It also provides a more expressive API that is great to use in Swift, with improved Swift concurrency and Codable support. With this year’s releases, the MXMetricManager API is considered legacy. ▶️ To learn more, watch Meet the new MetricKit. Discover new features in Xcode organizer Metric goals: Xcode organizer now provides a goal metric for Battery Usage, Disk Writes, Hang Rate, Hitches, Memory, and Storage metrics, allowing you to prioritize performance engineering across more areas. Generate recommendations: Quickly resolve the highest impact performance issues in your app by using Generate Recommendations for Crash, Energy, Disk Write, Hang and Launch diagnostics. Insights overview: The new insights overview in Xcode organizer summarizes high-impact performance regressions for metrics and diagnostic reports, helping you plan and prioritize performance engineering work. Storage metrics: Storage metrics are now available in Xcode organizer, allowing you to monitor your app's Documents & Data and App Size across releases and catch regressions in cache usage and bundle size. Hitches metric: The new Hitches metric replaces the Scrolling metric in the organizer and now displays hitches for all animations in your app, giving you a comprehensive view of animation performance. ▶️ To learn more about other advancements in Xcode, watch What’s new in Xcode 27. Improve app responsiveness with Instruments Foundation Models: The Foundation Models instrument is redesigned with a tree view that lets you drill into individual requests, inspecting tool call arguments and results, inference prompts and responses, and token statistics. Use it to understand caching behavior, measure latency, and optimize throughput. System Trace: System calls, VM faults, and thread states are now unified into a single plot, with a new blending algorithm that stays readable even at high density. Once you spot something worth investigating, left/right key navigation lets you follow a thread's activity step by step, and the inspector provides quick actions like pinning the thread that made another thread runnable. System Trace now also draws thread priority and QoS over time, making it easier to identify priority inversions and unexpected QoS degradations that affect responsiveness. Swift Concurrency: New Main Actor and Global Concurrent Executor tracks let you visualize running tasks and executor queue depth over time, making it easier to spot task scheduling delays and actor contention. Tasks are now grouped into collections for faster navigation. Swift Tasks, Actors, and Executors instruments can now surface Call Trees, Flame Graphs, and Top Functions scoped to each entity — so you can pinpoint exactly where concurrency overhead lives. Top Functions: Helper functions and runtime internals can be expensive but hard to spot in a standard call tree. The new aggregation mode in Top Functions surfaces any function's total execution time across the entire call stack, making it easy to identify and prioritize hidden hotspots. Run Comparison: Compare call tree data across builds to identify regressions and performance wins. Results can be explored as an outline, flame graph, or top functions — choose whichever view best fits your workflow. ▶️ To learn more about profiling your app with Instruments, watch “Profile, fix, and verify: Improve app responsiveness with Instruments” ▶️ To learn about Foundation Models optimization, watch “Debug and profile agentic app experiences with Instruments”. If you have any questions about using State Reporting or the new MetricKit, create a post on the forums. For help creating a post, see Tips on writing a forum posts.
Replies
0
Boosts
0
Views
1.7k
Activity
Jun ’26
TestFlight: StoreKit 1 and 2 return USD prices, but purchase sheet shows JPY
I'm investigating a price/currency mismatch in a TestFlight app. Environment: iPhone 15, iOS 26.6.2 App version 0.4.2 (Build 47), distributed through TestFlight Consumable product ID: line_stamp_8pack_1980 Diagnostic comparison: October 5, 2026, at 11:22:47 JST (UTC+09:00) For the same product, all three product lookup paths returned price 11.99, currency USD, and display price $11.99: StoreKit 1: SKProductsRequest / SKProduct StoreKit 2: Product.products(for:) expo-iap: fetchProducts The direct StoreKit calls were made through native Swift diagnostics in the app. All three lookups succeeded without errors. StoreKit 2 reported storefront country USA and ID 143462 before and after its lookup. expo-iap also reported USA before and after its lookup. StoreKit 1's storefront was unavailable before its request. Afterward, it reported USA, with storefront identifier "143462-9,29". Our diagnostic initially labeled this as a storefront change, but an unavailable-to-available result does not establish an actual country change. During the same testing session, Apple's purchase confirmation sheet for this product displayed ¥1,980 and stated that the purchase was for testing only. I canceled the sheet without completing the purchase. The Media & Purchases account's country/region is Japan. App Store Connect pricing for this product is ¥1,980 in Japan and $11.99 in the United States. What could cause the product lookup APIs to return the US storefront price while the purchase confirmation sheet displays the Japanese price? What additional diagnostics should I collect to identify the cause and obtain a product price consistent with the purchase sheet? Thank you.
Replies
0
Boosts
0
Views
221
Activity
4h
Custom Installer Plugin (x86_64 bundle) is not loaded on macOS 26A428 / 25G229 / 24H23, causing an installer GUI pane to be skipped
Summary A third-party PKG installer that ships a custom Installer Plugin no longer displays one of its selection panes. The plugin bundle appears not to be loaded, so the pane that it provides is silently skipped and the user cannot choose the intended installation option. This behavior started with recent macOS releases and did not occur on the immediately preceding versions, so it looks like a regression. Environment Machine: MacBook Pro 14-inch (M3) Affected builds: macOS 27.0 (26A428) macOS 26.7 (25G229) macOS 15.8 (24H23) Not affected: macOS 26.6 and earlier macOS 15.7 and earlier Reproducibility: every time Plugin binary: Mach-O 64-bit bundle, x86_64 only (no arm64 slice) Steps to Reproduce Download the Epson iProjection Ver.4.04 installer from the vendor support site: https://support.epson.net/setupnavi/?LG2=EN&OSC=MI&PINF=vpapp&MKN=EB-770Fi Mount the downloaded disk image and run the PKG installer. Step through the installer GUI and observe the pane transitions. Expected Result The installer GUI shows the "Application type" selection pane provided by the bundled Installer Plugin. Actual Result The "Application type" pane is never shown. The installer proceeds as if the plugin did not exist, and the user cannot select the installation type. What I Checked 1. The plugin is present inside the PKG pkgutil --expand-full PKG_PATH DEST_DIR The expanded payload contains the plugin bundle and its Mach-O executable under Contents/MacOS. 2. Architecture of the plugin binary file DEST_DIR/PluginName.bundle/Contents/MacOS/PluginName Result: Mach-O 64-bit bundle x86_64. It is a single-architecture binary with no arm64 slice. 3. The plugin is actually touched at install time sudo fs_usage -w -f filesys InstallerRemotePluginService-x86 opens the plugin executable inside the installer's temporary directory (a path under /private/tmp/com.apple.installer* ). So the plugin is reached as a load target, but the pane still does not appear. 4. Code signature validation When the installer is launched directly from the mounted disk image, code signature validation fails with: Too many levels of symbolic links My working theory is that the bundle contents are turned into symbolic links when the plugin is expanded, and that this causes codesign validation to fail, so the plugin is rejected before it can register its pane. 5. Code evaluation by syspolicyd log stream --info --debug --predicate 'process == "syspolicyd"' GK package assessment, GK process assessment and GK performScan entries are present, so Gatekeeper evaluation itself is running. The following also appears: Error Domain=NSOSStatusErrorDomain Code=-67062 Unsigned code in: PST: (path: REDACTED), (team: (null)), (id: (null)), (bundle_id: (null)) The PST path is anonymized in the log, so I could not confirm that this particular assessment refers to the plugin bundle. 6. XProtect evaluation results differ between versions log stream --info --debug --predicate 'process == "syspolicyd"' On the versions where the installer works correctly, the GK Xprotect results lines explicitly include a file URL pointing at the plugin bundle inside the installer temporary directory. On the affected builds, searching the same log for the plugin bundle name returns zero matches. That suggests the bundle is not being processed as an XProtect evaluation target at all on the newer builds. Question Was there a change in how Installer Plugins are expanded or validated in these releases, in particular around symlinked bundle contents or single-architecture x86_64 plugins? Any guidance on the supported way to ship an Installer Plugin so that it is still loaded on current macOS would be appreciated.
Replies
2
Boosts
0
Views
633
Activity
7h
Can a Third-Party App Using Critical Alerts Display a Full-Screen Emergency Alert Like iOS Emergency Alerts?
We are considering developing an iPhone application for workers operating in environments where safety is critical and notifications may involve life-threatening situations. We understand that Apple's Critical Alerts feature can deliver notifications with audible alerts even when the device is muted or Focus mode is enabled. However, we would like to know whether it is possible for a third-party app using Critical Alerts to present an emergency alert directly on the screen in the foreground, similar to the way iOS displays government-issued emergency alerts such as Earthquake Early Warnings (EEW). Specifically, can a third-party application trigger a full-screen emergency alert that immediately appears over other applications, rather than relying solely on a notification banner and alert sound? If this is not possible, are there any Apple-supported mechanisms or APIs that allow life-safety applications to provide a comparable user experience for urgent emergency notifications? We would appreciate any clarification regarding the capabilities and limitations of Critical Alerts for life-safety use cases.
Replies
0
Boosts
0
Views
234
Activity
8h
WCSession.sendMessage is crashing when a reply or error handler is attached, why?
The following code should send a message from the watch to the iPhone. Unfortunately, it is crashing. I have no clue why. if WCSession.isSupported() { let session = WCSession.default if ((session.activationState == .activated) && session.isReachable) { session.sendMessage(["SimpleMessages":["start"]], replyHandler:{reply in _ = 0 }, errorHandler:nil) } } If the reply handler is set to nil, the code does not crash. Anyway, in both cases the message is correctly sent from the watch to the phone. The code itself is run on the main thread (verified). I am running watchOS 26.6 and iOS 27. Here is the crash : Stack trace
Replies
0
Boosts
0
Views
62
Activity
9h
iOS 27 simulator never shows the AlarmKit permission prompt
Spent a good while debugging my own alarm code before working out the problem wasn't mine, so here it is in case someone's about to do the same thing. iOS 27 simulator, erased, clean install. requestAuthorization() comes back .denied and you never get a permission dialog at all. I had XCUITest sitting there watching SpringBoard for an Allow button over a bunch of runs, nothing. You can grant it manually in Settings and then authorizationState says .authorized, so the permission itself works, it's just the prompt that doesn't happen. On my actual phone (13, same 27.0) everything's normal, it schedules and rings and the alert comes up with snooze and stop on it. Then I went back to a 26.3 sim to compare and that one's worse here. SpringBoard keeps crashing, every few minutes, same thing each time: -[TLAlertQueuePlayerController _prepareAudioEnvironmentForStateDescriptor:isForMusicPlayback:] Unrecognised selector, SIGABRT, while it's trying to play the alert tone. It did that on a device I'd just erased with my app not even installed yet. Has anyone got the AlarmKit prompt to show up on 27 at all? Flag, particular device, entitlement, something in the plist I'm missing? And if you did grant it by hand there, do alarms actually fire afterwards on the sim? I never got far enough to find out, I just moved to the phone. Also curious whether anyone else sees that ToneLibrary crash on 26.3 under macOS 27. The AlarmKit wrapper I was poking at when I hit this is a free MIT gist, auth handling and deterministic alarm ids and the cancel-then-schedule ordering that got me earlier in the week: https://gist.github.com/yakubmurcek/61d8e3a60eb81e2c1f785010b4aa46de
Replies
0
Boosts
0
Views
74
Activity
12h
Dual-stack UDP socket bound to port 0 can get a port already in use on 127.0.0.1 (FB25058707)
I filed FB25058707 and wanted to make sure it reaches the right people, because it causes silent datagram loss that's hard to trace. On macOS, when a dual-stack UDP socket (AF_INET6 with IPV6_V6ONLY=0) binds [::]:0, the kernel sometimes gives it a port that an AF_INET socket already has bound to 127.0.0.1. Datagrams sent to 127.0.0.1 on that port then go to the AF_INET socket, so the dual-stack socket never receives them. An explicit bind of the same socket to that port fails with EADDRINUSE; only port-0 assignment hands it out. This program binds 1000 AF_INET sockets to 127.0.0.1:0, then binds dual-stack sockets to [::]:0 and checks where a datagram to 127.0.0.1:port lands whenever the port is already held. It's loopback only and runs in a few seconds: /* * A dual-stack UDP socket (AF_INET6, IPV6_V6ONLY=0) bound to [::]:0 can be * assigned a port already bound by an AF_INET socket on 127.0.0.1. Datagrams * to 127.0.0.1:port then reach the AF_INET socket, not the dual-stack one. * Loopback only. Build: cc -O2 -o dualstack_port0 dualstack_port0.c */ #include <arpa/inet.h> #include <errno.h> #include <netinet/in.h> #include <stdio.h> #include <stdlib.h> #include <string.h> #include <sys/resource.h> #include <sys/socket.h> #include <sys/time.h> #include <unistd.h> #define HELD 1000 #define TRIALS 2000 static int held[65536]; static void die(const char *what) { perror(what); exit(1); } static int port_of(int s) { struct sockaddr_storage ss; socklen_t len = sizeof(ss); if (getsockname(s, (struct sockaddr *)&ss, &len) != 0) die("getsockname"); if (ss.ss_family == AF_INET) return ntohs(((struct sockaddr_in *)&ss)->sin_port); return ntohs(((struct sockaddr_in6 *)&ss)->sin6_port); } static int bind_v4(in_addr_t addr) { int s = socket(AF_INET, SOCK_DGRAM, 0); if (s < 0) die("socket AF_INET"); struct sockaddr_in sin = { .sin_len = sizeof(sin), .sin_family = AF_INET, .sin_addr.s_addr = addr }; if (bind(s, (struct sockaddr *)&sin, sizeof(sin)) != 0) die("bind AF_INET"); return s; } static int bind_dual(void) { int s = socket(AF_INET6, SOCK_DGRAM, 0), off = 0; if (s < 0) die("socket AF_INET6"); if (setsockopt(s, IPPROTO_IPV6, IPV6_V6ONLY, &off, sizeof(off)) != 0) die("IPV6_V6ONLY"); struct sockaddr_in6 sin6 = { .sin6_len = sizeof(sin6), .sin6_family = AF_INET6, .sin6_addr = in6addr_any }; if (bind(s, (struct sockaddr *)&sin6, sizeof(sin6)) != 0) die("bind AF_INET6"); return s; } /* Returns 1 if s receives token within 100ms, skipping other datagrams. */ static int got(int s, const char *token) { struct timeval tv = { .tv_sec = 0, .tv_usec = 100000 }; if (setsockopt(s, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv)) != 0) die("SO_RCVTIMEO"); char buf[64]; for (;;) { ssize_t n = recv(s, buf, sizeof(buf) - 1, 0); if (n < 0) { if (errno == EAGAIN || errno == EWOULDBLOCK) return 0; die("recv"); } buf[n] = 0; if (strcmp(buf, token) == 0) return 1; } } int main(void) { struct rlimit rl; if (getrlimit(RLIMIT_NOFILE, &rl) != 0) die("getrlimit"); rl.rlim_cur = rl.rlim_max < 4096 ? rl.rlim_max : 4096; if (setrlimit(RLIMIT_NOFILE, &rl) != 0) die("setrlimit"); memset(held, -1, sizeof(held)); for (int i = 0; i < HELD;) { int s = bind_v4(htonl(INADDR_LOOPBACK)), p = port_of(s); if (held[p] >= 0) { close(s); continue; } held[p] = s; i++; } int sender = bind_v4(htonl(INADDR_LOOPBACK)); for (int dual = 1; dual >= 0; dual--) { int collisions = 0, to_held = 0, to_wild = 0; for (int i = 0; i < TRIALS; i++) { int w = dual ? bind_dual() : bind_v4(htonl(INADDR_ANY)), p = port_of(w); if (held[p] >= 0) { collisions++; char token[32]; snprintf(token, sizeof(token), "%d-%d", dual, i); struct sockaddr_in to = { .sin_len = sizeof(to), .sin_family = AF_INET, .sin_port = htons(p), .sin_addr.s_addr = htonl(INADDR_LOOPBACK) }; if (sendto(sender, token, strlen(token), 0, (struct sockaddr *)&to, sizeof(to)) < 0) die("sendto"); to_held += got(held[p], token); to_wild += got(w, token); } close(w); } printf("%s: %d/%d wildcard binds got a port held by a 127.0.0.1 socket; the probe reached that socket %d times, the wildcard socket %d times\n", dual ? "AF_INET6 V6ONLY=0 [::]:0" : "AF_INET 0.0.0.0:0 ", collisions, TRIALS, to_held, to_wild); } return 0; } On macOS 27.0 (26A428): AF_INET6 V6ONLY=0 [::]:0: 122/2000 wildcard binds got a port held by a 127.0.0.1 socket; the probe reached that socket 122 times, the wildcard socket 0 times AF_INET 0.0.0.0:0 : 0/2000 wildcard binds got a port held by a 127.0.0.1 socket; the probe reached that socket 0 times, the wildcard socket 0 times macOS 15.8.1 x86_64 gives the same pattern, and a Go version of the test reproduces on 15.7.9 and 26.6.2 as well. FreeBSD 15.1 gives 0/2000 with a dual-stack socket. From the public XNU source (xnu-12377.121.6), in6_pcbsetport checks candidate ports with in6_pcblookup_local, which skips PCBs without INP_IPV6, while in6_pcbbind does an IPv4 PCB lookup for dual-stack wildcard binds. That would explain why an explicit bind is refused but port 0 isn't. This is the cause of the long-standing Go issue golang/go#67226, since Go's net.ListenUDP("udp", 0.0.0.0:0) creates exactly this socket, and of intermittent failures in QUIC client tests. Using an AF_INET socket for IPv4-only traffic avoids it, but there's no workaround for a socket that needs both families on one port.
Replies
0
Boosts
0
Views
74
Activity
12h
How can I get the top right aligned transaction amount in iOS spotlight like how Wallet has things setup?
iOS 27, See image below. From top to bottom I'm using: displayName containerDisplayName contentDescription I haven't found a way to remove the transaction amount from my containerDisplayName and display it in the top right with some other CSSearchableItemAttributeSet value. Is it even possible?
Replies
1
Boosts
0
Views
400
Activity
12h
Title: Security-scoped folder bookmarks after rename or Trash: APFS vs exFAT/FAT32
I’m developing a sandboxed macOS app that needs persistent, read-only access to a user-selected folder. We are observing different behaviour between APFS and FAT32/exFAT after renaming the folder or moving it to Trash. The main problem is that the app can still track the folder while running, but cannot reliably restore the connection or identify its location after relaunch. Environment macOS 27.0.1 (26A434) Xcode 27.1 (27A9269) App Sandbox and user-selected file access enabled Folder selection through SwiftUI fileImporter Bookmark creation: .withSecurityScope and .securityScopeAllowOnlyReadAccess Bookmark resolution: .withSecurityScope The selected items are ordinary folders, not volume roots. Filesystem comparison APFS: the tested workflows appear to work as expected, including restoration after relaunch. exFAT: we have reproduced both bookmark renewal failure after a rename and loss of the “in Trash” classification after relaunch. FAT32: we have observed automatic bookmark renewal failures after a rename. The detailed debugger trace and Trash reproduction below were collected specifically on exFAT. Rename reproduction Select a folder through the system picker. Create and persist a read-only security-scoped bookmark. Resolve the bookmark and start accessing the resolved URL. Retain that URL and keep its security scope active throughout monitoring. Rename the folder in Finder while the app remains running. Attempt to create an updated bookmark for the same folder. The monitor retains an O_EVTONLY directory descriptor. After the rename, F_GETPATH returns the correct new pathname, and runtime identity checks still match the monitored folder. However, creating a bookmark using a URL reconstructed from that new pathname fails. Calling startAccessingSecurityScopedResource() on the reconstructed URL returns false, while the original resolved URL’s scope remains active. The bookmark creation call uses: url.bookmarkData(options: [.withSecurityScope, .securityScopeAllowOnlyReadAccess], includingResourceValuesForKeys: nil, relativeTo: nil) Exact failure measured on exFAT LLDB shows that Foundation’s internal open(): Receives the correct new pathname. Uses flags 0, meaning O_RDONLY. Immediately returns -1. Sets errno to 1, EPERM, read immediately on the same thread. The correlated Foundation error reports: NSCocoaErrorDomain Code 256 Could not open() the item: [1: Operation not permitted] This is a failed read-only open during bookmark creation. We have not established which policy causes the EPERM. A log stream filtered for com.apple.sandbox.reporting / violation produced no report during reproduction. We understand that this does not exclude sandbox involvement. We also tested a native CFURL file reference retained from before the rename. It continued to follow the folder and match its identity, but security-scoped bookmark creation from that reference also failed. Reselection works, but requires user intervention Selecting the same renamed folder again through fileImporter allows creation of a new bookmark. That bookmark resolves, is not stale, and restores access after relaunch. Without reselection before quitting, the previously saved bookmark does not restore access to the renamed folder on the next launch. The app reports it as unavailable. Separate Trash reproduction on exFAT Move the monitored folder to Trash using Finder while the app is running. The app correctly identifies the folder as being in Trash. Quit the app, leaving the folder in Trash. Relaunch: the app reports the folder as unavailable. The folder remains in Trash on the same exFAT volume. It has not been restored or permanently deleted. We also encountered failures when inspecting the Trash relationship using FileManager.getRelationship(_:of:in:toItemAt:) with .trashDirectory. We have not established whether these observations share the cause of the rename failure. Questions What is the supported public-API approach to preserve security-scoped folder access across an external rename on exFAT/FAT32, including after relaunch? What should bookmark resolution return for a folder moved to Trash, and how should a sandboxed app distinguish that condition from an unavailable resource after relaunch? Are these expected filesystem limitations, problems in our API usage, or behaviours that should be reported as macOS bugs? What additional diagnostics would help distinguish them? Ideally, the solution would preserve the original folder authorization without requiring repeated reselection or access to the parent directory or entire volume. I have read Accessing files from the macOS App Sandbox. I also found this discussion of bookmark failures involving exFAT, but it concerns volume roots and an earlier macOS release, so I’m not assuming it explains our case.
Replies
3
Boosts
0
Views
116
Activity
13h
Apple Watch Ultra 2: headingAccuracy near 89° even with correct heading; intermittent 180° reversal
Apple Watch Ultra 2, watchOS 27.0, Xcode 27. I use CLLocationManager.startUpdatingHeading(), headingFilter=1 and CLHeading.magneticHeading directly, with no offset or GPS course. During surfing, my app and Apple Compass both showed an apparent error of about 180 degrees. The iPhone was not nearby or connected. Later, outside water, readings returned to normal. An analog compass on the opposite arm differed by about 30 degrees initially, then agreed. All saved Int(headingAccuracy) values were 89; it still displays 89 while the heading is correct. Raw fractional values were not saved. Is this an expected or sentinel value on watchOS? What calibration and diagnostics are recommended for the intermittent reversal? The app also uses an underwater-depth extended runtime session; its errors have not been linked to the heading issue.
Replies
0
Boosts
0
Views
81
Activity
14h
Supported pre-initializer capture and failure enforcement for macOS guests
SANITISED SUPPORTED MACOS CAPTURE API INQUIRY REVIEW CORRECTIONS APPLIED — DRAFT, NOT SENT Question ID: MACOS-PROTECTED-CAPTURE-PROVIDER-20261004-02 Purpose: identify supported public capabilities; no project acceptance or native-execution approval is requested. Is there a supported public API combination on Apple silicon for capturing unchanged Apple-signed clang, ld and codesign inside a macOS guest after authenticated loader bootstrap but before any initializer, resolver or other target code? Only individually authenticated and explicitly enumerated loader-bootstrap operations may execute before capture; no blanket system-library exemption is assumed. The required observer/enforcer must remain outside tested guest-root authority. Include compromise of the submitting host's administrator. Observation, enforcement, state, custody, revocation and expected admission pins must not rely solely on controls that administrator can forge, replace or recover; remote signing or storage of its assertions is insufficient. The barrier must bind the exact process and guest generation, stop all target threads and byte/mapping writers, and capture complete actual loaded images, shared-cache membership, mappings, segment/private relocated bytes and backing identities coherently. Absent, crashed or disconnected observers, failed captures and missing verified release must keep execution blocked or terminate it before forbidden instructions. Release must be evidence-verified, same-incarnation and one-use. Guest termination must integrate with closed admission and generation fencing against saved-state resume, clone and replay. Our previously supplied context is macOS 26.6.2/SDK 26.5, observed but unattested. We have not run native qualification. Please state required host/guest versions explicitly; an upgrade is not assumed. Current public component documentation establishes: ES_EVENT_TYPE_AUTH_EXEC is an image-execution authorization event. es_set_deadline_miss_mode with ES_DEADLINE_MISS_MODE_FAIL_CLOSED (setter introduced in macOS 27) covers missed authorization deadlines and full-queue drops. Does this also cover client crash, deletion, disconnect or unsubscription, and could any such combination enforce the required post-loader barrier? VZVirtualMachine.pause provides VM lifecycle pausing; stop provides destructive stop with completion/error reporting. VZGuestMemoryMapping (macOS 27) exposes DRAM ranges through custom Virtio devices; the overview describes Linux guests. Is supported macOS guest use available for this purpose, and what coherent-capture/other-writer guarantees exist? Please identify the exact supported symbols and deployment configuration, documented pre-entry ordering and failure guarantees, supported macOS guest applicability, and required entitlements/signing policy. Also state whether protection weakening, target re-signing or changed system components would be required. Such requirements are compatibility limitations, not permission to perform those changes. If the full capability is unsupported, identify the specific missing public interface or guarantee rather than proposing an unsupported workaround. Public references: https://developer.apple.com/documentation/endpointsecurity/es_event_type_auth_exec https://developer.apple.com/documentation/endpointsecurity/es_set_deadline_miss_mode(::) https://developer.apple.com/documentation/endpointsecurity/es_deadline_miss_mode_fail_closed https://developer.apple.com/documentation/virtualization/vzvirtualmachine/pause() https://developer.apple.com/documentation/virtualization/vzvirtualmachine/stop(completionhandler:) https://developer.apple.com/documentation/virtualization/vzguestmemorymapping https://developer.apple.com/videos/play/wwdc2026/224/ Only this sanitised text and its public references are intended for relay. No private artifacts, personal/host identifiers, credentials or logs are needed. A provider reply is capability evidence; implementation, actual bindings, independent qualification, Founder acceptance and activation remain separate.
Replies
0
Boosts
0
Views
77
Activity
19h
TestFlight: StoreKit 2 returns no consumables despite active agreements; HTTP 200 and empty product response
Hello, We are troubleshooting product discovery for three consumable In-App Purchases in our first iOS game, ION RUSH. All three remain unavailable in TestFlight. Environment and result: Physical iPhone 13, iOS 27.0.1 (24A446). App version 1.0 (80), installed through TestFlight. Direct native StoreKit 2; no RevenueCat or other purchase SDK. Product.products(for:) returns zero products before application filtering, without throwing an error. Earlier independent development-build diagnostics also returned zero products for batch and individual StoreKit 2 requests; SKProductsRequest reported all three identifiers as invalid. Checks completed: Product IDs exactly match App Store Connect: nova_pack_5, nova_pack_15, nova_pack_40. The explicit bundle identifier matches the app record and code; In-App Purchase is enabled for the App ID. All three consumables show Ready for Review, have prices and localizations, and are available in all 175 configured territories, including the US. Developer membership, Paid Apps Agreement, bank account and tax forms are active. The Account Holder checked the Developer account for outstanding agreement signatures; none were visible. The Developer Program agreement was accepted September 29. Tax forms were submitted October 3 and now show Active. The financial setup was only recently completed, so delayed activation remains a possibility. The release scheme has no local StoreKit Configuration override. TestFlight reinstallation, device restart and repeated product refreshes did not restore the products. A re-export of the exact build 80 archive with the original App Store Connect signing settings selected an explicit App Store profile with beta-reports-active=true and get-task-allow=false. This checks the signing configuration; the original uploaded IPA was not available for direct inspection. Selected storekitd messages from October 4, 2026 (UTC+3): 09:59:22.963356 Requesting Media API product batch ["nova_pack_15", "nova_pack_40", "nova_pack_5"] 09:59:22.990339 summary for task success {transaction_duration_ms=1, response_status=200, cache_hit=true} 09:59:22.991595 Ignoring empty product response The request targets amp-api.sandbox.apple.com/v1/catalog/us/in-app-purchasables with the correct bundle and product IDs. Its account mediaType is com.apple.AppleMediaServices.accountmediatype.appstore.beta. A second request one second later produced the same HTTP status, cache flag and empty-product message. We did not capture the raw HTTP response body. Local StoreKit configuration tests work, but we understand this does not validate the live Sandbox catalog. We also understand that prior IAP review approval is not required for Sandbox testing. Questions: What additional developer-side check would distinguish incomplete account activation, product configuration or cached catalog state in this situation? Has anyone resolved this after completing agreements/banking/tax, especially when the products were created before financial activation? What exact action or elapsed time resolved it? If all TN3186 checks pass, what evidence and official escalation route should we use to request investigation of the app-to-product catalog association? Related reports: https://developer.apple.com/forums/thread/849165 (same storekitd messages, but after membership lapse/renewal; our situation differs) https://developer.apple.com/forums/thread/844545 (zero StoreKit 2 products and invalid StoreKit 1 identifiers after TN3186 checks) We can provide further redacted diagnostics and account details privately to Apple. Thank you.
Replies
0
Boosts
0
Views
64
Activity
19h
Opening Hours for Map Routing
I'm looking to access Apple Maps place metadata, particularly opening hours to route a user between 3 points. Suppose point C opens in the morning and B in the evening, I'd make sure to route the user based on which place is open at the time, eg A => C => B I understand from this thread that opening hours is not something app integrations can export. I was also checking out the batch endpoint. While its not necessary to export the data or display it inline, I'm looking for ways that my app can consume or consider this when routing between multiple places.
Replies
0
Boosts
0
Views
26
Activity
19h
CloudKit Background Export After Internet Reconnects
I’m seeing a repeatable failure to export changes in the background with an NSPersistentCloudKitContainer private database on iPhone. While offline, I create an object and save its managed object context. I then leave the app and lock the phone. After Wi‑Fi reconnects, the change remains absent from the same app on my Mac. Opening the iPhone app causes it to sync and appear on the Mac. The unplugged sequence reproduces this. When I tried the same sequence with the iPhone plugged in, background sync worked. In a sysdiagnose from an unplugged occurrence: 16:44:21: The context saved the new object. 16:44:21: dasd queued the CloudKit export but reported networkPathAvailability = 0. 16:44:27: iOS suspended the app. 16:48:21: Wi‑Fi reported a satisfied path. Through 16:54:42: No subsequent export attempt appeared in the logs. Opening the iPhone app caused the change to appear on the Mac. In the same offline-to-online routine, a reminder created in Apple Reminders appears on my Mac without reopening Reminders on the iPhone; my app’s new object does not appear until I reopen my app on the iPhone. Is a queued NSPersistentCloudKitContainer export expected to run after connectivity returns while the app remains suspended and unplugged? If so, what should I check to learn why it did not run here? Or does Reminders receive background scheduling priority that third-party apps cannot use?
Replies
1
Boosts
0
Views
95
Activity
20h
Supported completeness and lifecycle guarantees for es_new_descendants_client
Hello Apple Developer Technical Support, I am evaluating es_new_descendants_client for a local command runner that must report success only after its workload and every process descended from that workload have exited. If observation is incomplete or ambiguous, the runner must report failure. This is a design inquiry, not a report of a reproduced operating-system defect; no entitled prototype has been tested. The proposed observer would create its client and subscribe to lifecycle notifications before launching any workload. It would maintain a registry using process-lifetime identities, add processes on creation and remove them on exit. An unmatched event, missing required field, detected loss or observer failure would invalidate the run. It would consider closure only after all registered workload processes had exited. We have not established that these rules are sufficient. Could you clarify which of the following properties are supported API guarantees, and identify any that applications must not rely on? A documented reference or an explicit statement that a guarantee is unavailable would both help. Please identify applicable macOS/SDK versions and any known version-dependent limitations. 1. Membership and creation-event coverage Does the observed subtree retain a process and all of its future descendants after its original parent exits, it is reparented, it double-forks, or it changes process group/session with setpgid or setsid? Could a process remain observable for exit while creation events for its children become invisible? For a workload launched after successful subscription, does every successful process-creation path—including fork, vfork and posix_spawn—produce a lifecycle event sufficient to register the new process before closure can be declared? Which event and identity fields should be used for each path, including a child that exits without a successful exec? Does the calling observer receive the necessary event for its own initial workload launch? 2. Ordering and the meaning of exit Is there a supported per-client ordering guarantee that every child-creation event from a process is delivered before that process's exit notification, including concurrent creation and exit? Can the child's events arrive before the event that introduces that child? Please distinguish kernel enqueue order, handler delivery order and any processing order the application must impose. At what lifecycle boundary is ES_EVENT_TYPE_NOTIFY_EXIT generated? Does it establish that the identified process can no longer execute or initiate writes, or can relevant activity continue after the notification? We would not equate process exit with filesystem durability or completion of work already delegated to other processes. 3. Muting and other visibility filters Does a newly created descendants client have default process, path or target-path mutes that can suppress fork/exit notifications? What supported sequence of configuration and inspection calls establishes complete lifecycle visibility before launch, including mute inversion and executable-path changes? Apart from subscription and muting, are there policy, security, rate-limit or client-type exclusions that can suppress those events? Which suppressed events, if any, are intentionally absent from the sequence counter rather than reported as drops? 4. Sequence numbers and loss detection The global_seq_num documentation requires message version greater than 4. Is that field guaranteed for descendants-client lifecycle messages? Do notifications concerning the calling observer and its descendants use the same per-client sequence? How can a client establish a valid initial baseline and detect loss before its first received message? Is every dropped subscribed, unmuted lifecycle event reflected in the next delivered sequence number? What counter reset, wraparound or client-recreation rules must be handled? Would the proposed registry rule make terminal loss fail safely—for example, a lost final exit leaves a process registered—under the supported ordering and visibility semantics? Or is there a counterexample in which the registry can become empty while an unobserved descendant survives? 5. Synchronization, observer failure and delegated work Does es_sync_client provide any loss/completeness information beyond draining preceding queued messages? Its documented callbacks also run for a destroyed or null client, so we would not interpret callback arrival alone as successful completion. Is there a supported mechanism to distinguish a healthy drain from invalidation? What does “instigates” cover for this client? In particular, can it observe or attribute work executed by existing launchd/XPC services, or by unrelated processes receiving file descriptors? We would treat such work as outside a lineage-only closure claim unless it is explicitly covered or independently excluded. Does this client provide any supported protection against a same-UID workload stopping, killing or otherwise interfering with its observer, or must that isolation be supplied separately? Observer failure would invalidate the run; we are not assuming ES supplies a write barrier for evidence files. 6. Supported cleanup and deployment Is there a supported public mechanism to signal a non-child descendant by process-lifetime identity, without a PID-reuse race between observing it and sending a signal? Is there a recommended approach if the observer cannot wait on that process? We do not want to depend on private libproc functions as an application contract. Finally, is this use case eligible for com.apple.developer.endpoint-security.client in a standalone signed command-line observer, and what supported signing/provisioning or packaging requirements apply? This is a request for guidance, not an entitlement application. Our central question is whether supported APIs can establish complete descendant-process closure under these constraints. If they cannot, we would appreciate a clear statement of that limitation or a supported alternative. Thank you. Documentation consulted: es_new_descendants_client es_sync_client global_seq_num es_process_t
Replies
5
Boosts
0
Views
713
Activity
1d
Restartable Sequences. What are they?
After scouring the XNU kernel source code, I came across restartable ranges [1]. They seem to be a task-level version of the the part of Linux's restartable sequences [2] for user requested synchronization [3] (akin to MEMBARRIER_CMD_RSEQ). Because of their differences, I would like to know more about how they work and what they are used for. From what I have gathered [4], they seem to be closer to RCU [5] that waits for eviction (as opposed to completion). But the fact that they are barely mentioned anywhere (see [4]) in the XNU source code I'd be really happy if you can point me to more information about them and how they compare to rseq (or rcu). What are the XNU devs planning on doing with them? [1] osfmk/kern/restartable.c: https://github.com/apple-oss-distributions/xnu/blob/f6217f8/osfmk/kern/restartable.c [2] https://criu.org/Restartable_Sequences [3] as opposed to (what I think is what makes rseq really cool) automatic eviction on preemption/CPU migration [4] there seems to be very little information online (including this forum) and the only places inside the XNU kernel source trees that aren't tests are in osfmk/kern/{thread,thread,sched_prim}.{c,h}, which doesn't really give much more information. [5] Read-Copy-Update: https://www.kernel.org/doc/html/latest/RCU/whatisRCU.html
Replies
2
Boosts
0
Views
415
Activity
1d
Empty Storekit Catalog Response
Hello all, I'm posting here today in hopes the internet can help me find a solution for an issue I'm having with integrating with subscriptions created in App Store Connect. I'm receiving no products back from StoreKit 2 for my list of product IDs. Things I've verified so far: No errors are coming from StoreKit The product IDs I'm requesting match the configured product IDs in the subscriptions The provisioning profile matches the bundle ID of the built app. The provisioning profile includes the in-app purchases capability. All subscriptions are priced, include localization, have an availability region set, and include a tax category. The subscriptions have been set for a week. Well over the typical one hour metadata update window. My banking, tax info, and paid apps agreement are up to date and active. I'm signed out of Media & Purchases and signed into a sandbox account under developer mode on the test device. The region of the sandbox account matches the region availability of the subscriptions. Under Signing & Capabilities in Xcode, my team matches the team the app is created under in App Store Connect, In-App Purchase is included, and we are signing with my team's certificate. The app under test is a production release build installed via Test Flight. Logging the StoreKit environment shows that it's in the sandbox and matches the region configured for the sandbox user and subscriptions Device: iPhone 14 OS: iOS 26.5.2 Thanks in advanced for any help and insight you may have.
Replies
0
Boosts
0
Views
264
Activity
1d
CarPlay Video entitlement pending for 15 days — is there an escalation path?
We submitted a request for the CarPlay Video entitlement (com.apple.developer.carplay-video) on September 15, 2026, and have not received an approval, rejection, or request for additional information after 15 days. We have already followed up through the original entitlement email thread and contacted Apple Developer Support several times. Across these exchanges, we have provided the same core information at least four times, including the entitlement Case-ID, submission date, business need, and confirmation email. However, several replies have simply asked us to provide the same information again. Developer Support has also confirmed that CarPlay entitlement requests are handled by a different team and that they do not have a direct contact or support channel for that reviewing team. At this point, is there any escalation path for a CarPlay Video entitlement request that has been pending without an update? Or is waiting several weeks currently normal for these requests? Any guidance from an Apple engineer or developers who have recently gone through the CarPlay Video entitlement process would be greatly appreciated. Thank you
Replies
1
Boosts
0
Views
83
Activity
1d
StoreKit 2 returns USD product metadata in TestFlight while the storefront is FRA/EUR
Hello, We would appreciate some guidance regarding an unexpected StoreKit currency result in a TestFlight build. Our iPhone language and region are both set to France. The Sandbox tester is also configured for France, and our subscription products have French availability and pricing configured in App Store Connect. In the TestFlight build we diagnosed, StoreKit reports the current storefront as France with EUR: storefront=FRA/143442/EUR However, all 10 subscription products are returned with USD product metadata: products=10/10 formatCurrencies=USD localeCurrencies=USD error=NONE Example: formatCurrency=USD locale=fr_US_currency_USD localeCurrency=USD display=1,99 $US price=1.99 We first observed this through Flutter's in_app_purchase integration. To determine whether the Flutter plugin was involved, we added a native StoreKit 2 diagnostic to the same TestFlight build. The native result was identical: receipt=sandboxReceipt storefront before=FRA/143442/EUR storefront after=FRA/143442/EUR products=10/10 formatCurrencies=USD localeCurrencies=USD error=NONE The issue appears specific to the TestFlight distribution. When the application is installed directly from the development computer, prices are returned in euros on the same device. We also tested with the regular Media & Purchases account signed out and a French Sandbox tester connected. Once the products loaded successfully, StoreKit still returned USD metadata. In another configuration, the application displayed the USD price while Apple's purchase sheet displayed the price in euros. We are using the price and formatting information returned directly by StoreKit. We do not want to infer the currency from the device region or perform a client-side currency conversion, because StoreKit should remain the authoritative source. Could you please help us understand: Is it expected for Storefront.current to report FRA/EUR while Product.priceFormatStyle.currencyCode, its locale currency, and Product.displayPrice use USD? Could a TestFlight or App Store Connect configuration cause product metadata to use a different currency from the current storefront? Is there another account, availability, pricing or distribution setting that we should verify? Is there a recommended way to refresh or invalidate the product metadata used by a TestFlight installation? We have already filed Feedback Assistant report FB24723329, which is currently under investigation. Thank you very much for any clarification or additional diagnostic steps you can suggest.
Replies
3
Boosts
1
Views
646
Activity
1d
iOS 27 CarPlay section headers disappear with detail text or images
Adding an image or detail text to a CPListSection makes the whole header disappear. With no detailText or headerImage With detailText or headerImage FB24061858 open but no response.
Replies
2
Boosts
2
Views
428
Activity
1d
In-App Purchases work in TestFlight but not during App Review
Hi everyone, I'm a new iOS developer, and my first app has been rejected twice because of In-App Purchase issues. Setup: Flutter, in_app_purchase 3.3.0, in_app_purchase_storekit 0.4.10 (StoreKit 1) One auto-renewable subscription and one non-consumable lifetime purchase Both products show "Ready for Review" in App Store Connect. Paid Apps Agreement is active. First review: The prices were visible on an iPad, but the subscription purchase failed (Guideline 2.1(b)). Second review: Neither product showed a price on an iPhone (Guideline 2.1(b)). Apple also noted missing subscription information (Guideline 3.1.2(c)). On my iPhone 15, both products load correctly and test purchases work in TestFlight using my regular Apple Account. Product IDs, pricing, availability, and localizations appear correct. My question: What could cause queryProductDetails / SKProductsRequest to return no products during App Review when everything works in TestFlight? Any suggestions would be greatly appreciated. Thanks! :)
Replies
0
Boosts
0
Views
129
Activity
1d