Posts under App & System Services topic

Post

Replies

Boosts

Views

Activity

In-App Purchases work in TestFlight but not during App Review
Hi everyone, I'm a new iOS developer, and my first app has been rejected twice because of In-App Purchase issues. Setup: Flutter, in_app_purchase 3.3.0, in_app_purchase_storekit 0.4.10 (StoreKit 1) One auto-renewable subscription and one non-consumable lifetime purchase Both products show "Ready for Review" in App Store Connect. Paid Apps Agreement is active. First review: The prices were visible on an iPad, but the subscription purchase failed (Guideline 2.1(b)). Second review: Neither product showed a price on an iPhone (Guideline 2.1(b)). Apple also noted missing subscription information (Guideline 3.1.2(c)). On my iPhone 15, both products load correctly and test purchases work in TestFlight using my regular Apple Account. Product IDs, pricing, availability, and localizations appear correct. My question: What could cause queryProductDetails / SKProductsRequest to return no products during App Review when everything works in TestFlight? Any suggestions would be greatly appreciated. Thanks! :)
0
0
129
1d
Logitech MX Brio 4K webcam detected but no video on macOS 27 Golden Gate (Mac Studio M4)
Since upgrading to macOS 27 Golden Gate, my Mac Studio (M4) recognises my Logitech MX Brio 4K webcam, but no video feed is displayed. The camera appears to be detected by the system, but the video signal does not show up in: FaceTime Photo Booth Logitech Options+ I've spent quite a bit of time troubleshooting the issue, including following diagnostic steps suggested by Siri and Copilot, but everything points to a potential macOS-related problem rather than a hardware or configuration issue. Has anyone else experienced this with the MX Brio or other webcams on macOS 27 Golden Gate? I reported the issue to Apple through the Feedback app when Beta 1 was released, but so far I haven't received a response or found a workaround. Any insights or suggestions would be greatly appreciated. Thanks!
2
0
113
1d
Can watchOS apps access Apple-generated sleep stages in real time for a smart alarm?
I’m evaluating a native watchOS smart-alarm app and would like to clarify whether public APIs support its core requirement before building a prototype. The app would wake the user during a 20–30-minute window before their selected alarm time, using Apple Watch’s own sleep-stage classifications available through HealthKit’s sleepAnalysis category: Core, Deep, REM, and Awake. I have reviewed HKCategoryValueSleepAnalysis, HKAnchoredObjectQuery, HKObserverQuery, background delivery, and WKExtendedRuntimeSession’s Smart Alarm mode. However, I haven’t found documentation establishing when Apple-generated sleep-stage samples become available during an ongoing sleep session. Could you clarify: Are Apple-generated sleep-stage samples written to the Watch’s local HealthKit store during sleep, or only after the sleep session ends or subsequent processing? If available during sleep, is there any documented update cadence or latency that would make them suitable for a smart alarm? Should the latest sample be treated only as a retrospective classification rather than the current sleep stage? Can an app query these samples during a Smart Alarm extended runtime session while the Watch is worn and unlocked, with its display off and Sleep Focus enabled? Are there relevant execution or data-access restrictions? If this use case is unsupported, is there any public API that exposes Apple’s current sleep-stage estimate? If not, which Feedback Assistant category is appropriate for requesting this capability? The intended approach queries HealthKit directly on Apple Watch, without depending on Watch-to-iPhone synchronization, and retains a fixed latest wake-up time as a fallback. This is an API feasibility question, not a reproduced bug. I haven’t yet built or tested a prototype. Thank you.
0
0
58
1d
MacOS HomeKit private (and still useable) application
How do I write a macOS (no need for i/Pad/OS at all) application which supports HomeKit for my own private use only? My original idea was simply to write it non-provisioned, which would solve all problems perfectly. Nevertheless, that, triple alas, seems not possible (https://developer.apple.com/forums/thread/849288). Provisioned one built locally has a lot of problems, among which there are e.g., big hurdles to run it at my other Macs (https://developer.apple.com/forums/thread/848903?answerId=907702022#907702022) an extremely limited expiration date A reasonable solution would be a creation of a provisioning profile which would include an expiration date in a far future and also IDs of my other computers; alas, far as I understand, this does not seem to be possible with a Personal Team, as detailed in https://developer.apple.com/forums/thread/848903?answerId=907568022#907568022. Whilst a sort of solution might be the nuclear one, it does not feel right the slightest — I need just to run my own app, nothing more, and whilst naturally I gladly accept all the possible dangers of code I wrote myself, I definitely would not want to get completely vulnerable where all the other apps (and other threats) in the world are concerned. I've checked also the Unlisted distribution; far as understand it properly, won't do either, e.g., since it will be declined ... if your app is in a beta or prerelease state — the application is fully intended to be used locally for months or even years in this state. Besides, even Unlisted apps must go through Review, and when I bump to a need to make any kind of change, I want simply do that locally and launch my new version immediately without any Review hassle. Also, in this case the otherwise important privacy issues like e.g., determining the proper computer name (https://developer.apple.com/forums/thread/813853?answerId=874075022#874075022) are of absolutely no importance. Are there other, more reasonable options? What's the proper solution, after all? Thanks!
0
0
117
2d
Apple Watch Ultra: Does an underwater compass app require the full Submerged Depth and Pressure entitlement to operate below 6 meters?
Hi there, I'm planning to develop a simple underwater compass app for Apple Watch Ultra 2, intended for recreational scuba diving down to 40 meters. The app itself does not need depth or pressure measurements beyond 6 meters. Its primary function is compass navigation using heading data. During a dive, however, I would like the app to: remain frontmost and visible throughout the dive; use Water Lock; use an underwater-depth WKExtendedRuntimeSession; continue receiving compass heading updates; allow interaction through physical controls such as the Digital Crown and Action Button; remain operational below 6 meters, potentially down to 40 meters. I understand that the Shallow Depth and Pressure capability limits CMWaterSubmersionManager depth/pressure data to approximately 6 meters, while access to depth/pressure data down to 40 meters requires the full Submerged Depth and Pressure entitlement. My question is: If my app does not require depth/pressure measurements beyond 6 meters, is the full Submerged Depth and Pressure entitlement still required simply to keep the underwater extended runtime session, UI, compass heading updates, and physical-control interaction working below 6 meters? In other words, does the 6-meter entitlement limit apply only to depth/pressure data, or does it also limit the ability of an underwater compass app to remain operational during a scuba dive below 6 meters? Target hardware: Apple Watch Ultra 2. Thanks in advance!
2
0
452
2d
What is the supported DriverKit Stop/drain sequence for an IOUserClient operation queue?
Environment: macOS 26.6.2 (25G83), Apple silicon Xcode 26.6 (17F113) DriverKit SDK 25.5 I am implementing a DriverKit IOService with an IOUserClient. This is a lifecycle and object-ownership question independent of the device protocol. The intended design admits at most one user client during a provider lifetime. Lifecycle methods run on the provider’s default queue, while IOUserClient ExternalMethod requests run on a separate serial IODispatchQueue. At most one device request may be in flight. The shutdown invariant we need is: Stop accepting new requests. Allow every accepted request to complete exactly once, or cancel it. Observe completion of the operation queue’s cancellation handler. Call the inherited Stop implementation last. Perform no provider access afterward. The relevant public documentation is: IOService::Stop: https://developer.apple.com/documentation/driverkit/ioservice/stop IODispatchQueue::Cancel: https://developer.apple.com/documentation/driverkit/iodispatchqueue/cancel IOService::SetDispatchQueue: https://developer.apple.com/documentation/driverkit/ioservice/setdispatchqueue For the normal path, the proposed sequence is conceptually: Stop(provider): close request admission operationQueue->Cancel(cancellationHandler) wait for the cancellation handler from the separate queue super::Stop(provider) I need clarification of the complete supported public API contract: If IODispatchQueue::Cancel returns a non-success result, is its cancellation handler still guaranteed to execute? If it is not, what supported action lets Stop keep the provider and user client valid until previously accepted work is no longer capable of accessing them? Is it supported for the provider and its one user client to share the provider-owned serial operation queue? If the IOUserClient stops independently, must it own and cancel a separate queue, or is there a supported per-client drain mechanism that does not cancel provider-owned work? Is the driver’s public IOService::Stop override guaranteed to run on every termination path where accepted user-client work must be drained, including when the provider is already inactive or the DriverKit server has slept? If not, which public lifecycle callback supplies that drain point? Is blocking the provider’s default queue inside Stop while awaiting the cancellation handler from a separate operation queue the supported interpretation of “wait for your cancellation handlers”? If not, what public continuation mechanism should be used before calling inherited Stop? We also observed one power-management panic after sleep/wake: HiMDScsiDriver::setPowerState(..., 0 -> 4) timed out after 20342 ms The DEXT does not currently override SetPowerState. This panic motivates the lifecycle review, but I am not treating it as proof that the Stop/drain design caused the timeout. I am looking specifically for a supported public DriverKit sequence. I do not want to rely on private framework entry points or infer object-lifetime guarantees from a successful build or experiment.
7
0
1.4k
2d
401 error registering sandbox domain with Web Merchant Registration API
Hi, We recently applied for the Web Merchant Registration API and created our platform integrator ID. I am trying to register a domain in sandbox with the API: POST https://apple-pay-gateway-cert.apple.com/paymentservices/registerMerchant Content-Type: application/json { "domainNames": ["<URL>"], "partnerInternalMerchantIdentifier": "<merchant_id>", "partnerMerchantName": "<merchant_name>", "encryptTo": "<platform_integrator_id>" } Client certificate is provided via curl --cert/--key; the TLS 1.3 handshake completes successfully — the server requests the client cert, our Certificate + CERT verify are accepted, and the connection is established. But the response is { "statusMessage": "Payment Services Exception Unauthorized", "statusCode": "401" } How do I go about debugging this?
0
0
281
2d
CarPlay suppresses local notification sound app-wide — does a Live Activity alert behave differently?
I've confirmed through controlled testing that local notification sound is suppressed app-wide whenever CarPlay is connected, for an app with no CarPlay entitlement. Tested: Sound plays normally with CarPlay disconnected Sound is silent with CarPlay connected — confirmed by repeatedly connecting/disconnecting CarPlay with the identical notification, nothing else changed No difference with phone locked vs. unlocked No difference with Driving Focus on vs. off No difference with interruptionLevel set to .active vs. .timeSensitive Device: iPhone 13, iOS 26.6.2. Head unit: 2024 Toyota Tacoma (CarPlay). My app has no CarPlay entitlement (not navigation/audio/EV/parking/food- ordering), so I suspect this suppression may be intentional — but I can't find it documented anywhere. Given that, I'm looking at iOS 26 Live Activities as an alternative, since Apple's docs say a Live Activity can appear on the CarPlay Dashboard without a CarPlay entitlement. But I can't find documentation on: Whether a Live Activity push-to-start or update plays an audible sound when the phone is locked and CarPlay is connected. Whether Live Activity content backed by data-protection class A/B storage reliably renders in this state (separate widget guidance warns this "likely won't work in CarPlay" since phones are usually locked — unclear if this applies to ActivityKit content specifically). Has anyone tested this, or know if it's documented somewhere I'm missing? Trying to figure out if Live Activities are a viable path to a driver- audible alert for a non-CarPlay-entitled app, before I invest more engineering time in it.
0
0
114
2d
iPhone sync on MacOS Golden Gate 27.0.1 (26A434) caused data exposure out of sandbox
Hi guys, I connected iPhone using USB cable to Mac running Golden Gate 27.0.1 (26A434) and in Finder I selected iPhone to open sync page I was looking at Files tab and trying to get data from one of the apps. As I was doing that at certain point after disconnecting and connecting USB cable I wanted to avoid sync, so when dialog "Trust this computer" showed up on iPhone, I tapped "Cancel". Then when disconnecting cable and connecting again, it started sync and under Files under the app in treeview original data disappeared (a database file and 2 folders with images) and iTunes_Control and Recordings folders showed up instead. I copied these folders to my Mac and there were files containing data. It looks like instead of Documents folder belonging to the app the sync mapped completely different storage location, which should have been protected by sandbox (I'm assuming). I clicked "Eject" icon in Finder, disconnected cable, connected again and it started sync, but ultimately failed with an error that some file does not exist. That dialog presented title with a completely different name than is the name of my iPhone, it presented something like Robert's iPhone, which is a name usually chosen by default when setting up new iPhone. I tried sync 3 times, but nothing helped to fix the problem. Has anyone seen this issue? I completely shutdown iPhone and started again. Sync completed successfully and under that app its original data showed up again (database file and 2 folder with images), iTunes_Control and Recordings folders didn't show up. Is it possible that sync mounted wrong location and exposed data that should have been protected by sandbox and never exposed this way and under wrong app?
0
0
147
2d
macOS guest freezes after update reboot on M4 host with Virtualization.framework
macOS guest (Virtualization.framework) freezes with all vCPUs halted right after a macOS update reboot - 3/3 on a macOS 26.7.1 (25G309) M4 host, seen with both UTM and Parallels Summary On a macOS 26.7.1 (25G309, beta/seed build) host with an Apple M4, every macOS guest that runs an in-place macOS update freezes at the same point: the in-OS phase of the update completes and reports success, the guest requests a reboot, records a shutdown stall 9 seconds later, reboots twice, shows the update progress screen for about a minute, and then stops. All four vCPUs enter WFI and never wake, paravirtualized graphics stops submitting, no I/O is pending on the host side, and no host service logs an error. The VM never recovers and has to be killed. Reproduced 3 out of 3 times, under two different front-ends (UTM and Parallels Desktop) and two guest versions (15.7.x and 26.6.2). Environment Host: iMac (Mac16,3), Apple M4, 16 GB RAM, macOS 26.7.1 build 25G309 (seed channel), installed the evening before the first failure. Primary guest: macOS 15.7.9 (24G830), hardware model VirtualMac2,1, 4 vCPUs, 6 GB RAM, 90 GB raw disk image (virtio-blk) stored on an external USB SSD. Networking bridged to the built-in Ethernet port. Devices enabled: memory balloon, audio, entropy, clipboard sharing; display 1920x1200 with dynamic resolution. Front-end for the primary case: UTM [version], Apple Virtualization backend. Guest was the only VM running, cold-booted, window open. Update being applied: MSU_UPDATE_24H23_patch_15.8_minor (15.7.9 -> 15.8). Other cases: a macOS 26.6.2 guest under UTM; a macOS 15.7.7 -> 15.8 guest under Parallels Desktop 26.4.2 (57518). Steps to reproduce Cold-boot a macOS 15.7.9 guest under Virtualization.framework, as the only VM on the host. In the guest: System Settings > Software Update > install macOS 15.8. Let it reboot. Expected The guest installs the update and boots into 15.8. Actual — timeline of the primary case (R = the moment Software Update requested the reboot; absolute timestamps are in the attached logs) R-23 min to R-5 min: UpdateBrainService prepares the update inside the guest, writing about 25 GB (two "disk writes" resource reports: 16.5 GB then 8.5 GB). No errors. R-1:56: post-logout install configured; disk space check passes (5.7 GB required, 40.7 GB free). R-1:44: "SUOSUPostLogoutInstallOperation: Applying MSU update". R: "Applied MSU update"; FileVault stash committed ("kAppleFDEKeyStore_commitStash success"); "Rebooting (success = 1, displayAsleep = 0, shutdown = 0)". This is the last line the guest ever writes to install.log. R+9 s: the guest writes a shutdown_stall diagnostic report. R+10 s: host sees ParavirtualizedGraphics "Device reset" / "PGDisplayNub[0]: Destroyed" (reboot #1). R+1:20: second device reset (reboot #2), 70 s after the first. On the host, the vmnet interface is torn down and recreated with no error, the AppleVirtualPlatformIdentity service completes boot attestation with no error, and the guest's graphics driver renegotiates ("Guest requested binary version: 209"). R+1:38: host logs "PGDisplay[0]: Change display mode to 3606x2254" — the guest is on the update progress screen. R+1:41 to R+2:25: the guest's six PGFifoThreads go idle one at a time. The progress bar stops partway. No further activity of any kind. R+11:35: spindump of the VM host process (com.apple.Virtualization.VirtualMachine): 0.042 s of CPU over a 5 s sample all four com.apple.virtualization.thread.cpu-N threads in Hv::Vcpu::run() -> HvCore::Hypervisor::VcpuStateManager::wait_for_interrupt() -> __psynch_cvwait cpu-0/cpu-1 wake on a ~20 ms timer tick and return to WFI; cpu-2/cpu-3 had not run for seconds no thread in any file read, write or fsync (no host I/O outstanding) PGFifoThreads last ran 550–614 s earlier process state Ss (sleeping), not U Host kernel log for the window: no USB, APFS, I/O error, timeout or reset entries. No hardware video decoder (AppleAVD) errors. The VM was left for over an hour with no change, then killed. Second case (same host, same day, UTM, guest macOS 26.6.2) Identical signature: two graphics device resets 69 s apart, display mode set 3 s after the second one, last graphics activity about a second later, then all vCPUs idle in WFI for ~6.5 hours until the VM was killed. Third case (same host, same day, Parallels Desktop 26.4.2, guest 15.7.7 -> 15.8) The guest was suspended in the middle of its update and resumed later. On resume ("-[_PGDevice willResumeWithSuspendState:error:]: Begin resume", preceded by "[VirtualMachineParameterBuilder] Failed to get auxiliary file identifier"), paravirtualized graphics never came back — its FIFO threads ran once and never again — and the guest's vCPUs sat in WFI. This may be a separate save/restore defect, but the end state is the same. What I believe is ruled out The in-OS phase of the update: it completed and reported success. Guest kernel panic: vCPUs are halted, not spinning, and there is no panic report on the guest's data volume. Disk space: 40.7 GB free in the guest at install time. Host storage stall: no uninterruptible wait, no I/O frames in the spindump, no kernel storage errors. Host hardware video decoder: no AppleAVD errors in the primary case. Host services: vmnet and AppleVirtualPlatformIdentity completed normally seconds before the hang. Guest memory: 6 GB allocated. Not yet isolated The VM images live on an external USB SSD; not yet reproduced from internal storage. The memory balloon, audio and clipboard-sharing devices were enabled; not yet reproduced with them disabled. A third-party VPN client was running on the host (guest networking is bridged, so guest traffic bypasses the host tunnel, but host firewall rules could still affect bridged frames). I don't have a confirmed-good in-place guest update on this machine from before 26.7.1, so I can't state with certainty that this is a regression. Frequency 3 of 3 attempts on this host. Attachments / available on request spindumps of the hung VM host process (primary case and second case) host unified-log excerpts for both hang windows the guest's full install.log the guest's shutdown_stall report and the two UpdateBrainService disk-writes reports sysdiagnose captured while hung, if obtained Has anyone seen macOS guests stop at this point on the 26.7.x seeds? If you can reproduce, your host build, hypervisor, and whether the VM image is on internal or external storage would be useful to compare.
4
3
314
2d
IPSW for 15.7.7 missing
Hi, we're only seeing 15.6.1 IPSW available for VMs. Where can we find latest and secure versions of macOS IPSW on https://updates.cdn-apple.com/*/fullrestores/ ? Is there an official list somewhere that Apple provides? We need to be sure we can create the latest 15.7.7 VMs with automation and not rely on inner VM upgrades of MacOS.
4
0
246
2d
Is there any official way for a Screen Time app outside the EU to access per-app usage data?
I'm developing a digital wellbeing app using FamilyControls and DeviceActivity. The core functionality of the app is to show the user their per-application Screen Time usage, including the application identity and duration (for example, Instagram — 1h 30m, YouTube — 45m). I understand that on iOS 26.4+, AuthorizationStatus.approvedWithDataAccess and DeviceActivityData.activityData(filteredBy:using:) provide access to non-tokenized application usage data. I also understand the current Apple documentation states that customer installations can only obtain approvedWithDataAccess on devices located in the EU with an Apple Account configured to an EU country or region, and that outside the EU the authorization status never becomes approvedWithDataAccess. My app and test device are based in Kazakhstan. My question is not about bypassing Apple's privacy model or implementing an undocumented workaround. I would like to know whether there is any official path for a legitimate third-party Screen Time / digital wellbeing app to obtain this data outside the EU, for example: an additional entitlement; a developer approval or application process; a regional exception; an alternative Apple-supported API; or any other official mechanism. We already have the Family Controls distribution entitlement approved and have enabled the Family Controls App and Website Usage capability. If no such mechanism exists, I would appreciate confirmation that the EU restriction is currently absolute for customer installations and that there is no additional entitlement or approval process available for developers outside the EU. The reason I am asking is that per-application usage is a core part of the application's functionality, so I want to make sure I am not missing an official Apple-supported option before designing around this limitation.
0
0
79
2d
macos 27 - EDOM error from setsockopt() for SO_LINGER socket option for values greater than 32767
On macos 27, there appears to be a change in the setsockopt() implementation for the SO_LINGER option. It looks like the implementation now imposes a different maximum limit on the value that is accepted for linger. Consider the trivial attached C program. Rename it from main.c.txt to main.c. Compiling it (using clang main.c) and running it (using ./a.out), on older versions of macos (like 26.x), it returns: ----------------------- MacOS version: 26.7.1 Kernel version: Darwin Kernel Version 25.6.0: Tue Aug 18 17:49:13 PDT 2026; root:xnu-12377.161.15.700.19~2/RELEASE_ARM64_T6000 ----------------------- SUCCESS - set SO_LINGER to value 10 SUCCESS - set SO_LINGER to value 42 SUCCESS - set SO_LINGER to value 1024 SUCCESS - set SO_LINGER to value 32767 SUCCESS - set SO_LINGER to value 32768 SUCCESS - set SO_LINGER to value 65535 SUCCESS - set SO_LINGER to value 65536 SUCCESS - set SO_LINGER to value 65578 However, on macos 27, this now fails with EDOM error ("Numerical argument out of domain") for values greater than 32767: ----------------------- MacOS version: 27.0.1 Kernel version: Darwin Kernel Version 27.0.0: Tue Aug 11 21:02:16 PDT 2026; root:xnu-13432.1.9~1/RELEASE_ARM64_T8112 ----------------------- SUCCESS - set SO_LINGER to value 10 SUCCESS - set SO_LINGER to value 42 SUCCESS - set SO_LINGER to value 1024 SUCCESS - set SO_LINGER to value 32767 FAILURE - failed to set SO_LINGER to value 32768, reason: Numerical argument out of domain FAILURE - failed to set SO_LINGER to value 65535, reason: Numerical argument out of domain FAILURE - failed to set SO_LINGER to value 65536, reason: Numerical argument out of domain FAILURE - failed to set SO_LINGER to value 65578, reason: Numerical argument out of domain I'm guessing this is an intentional change, but I wanted to confirm nonetheless. Should the documentation of SO_LINGER and SO_LINGER_SEC socket options, in man setsockopt, mention the acceptable value range for them? main.c.txt
2
0
113
2d
macos 27 - unexpected/new errno from BSD socket connect() when pending connections exceed backlog
Please consider the trivial C program attached to this thread. The code creates a socket() and listen()s for connections, but (intentionally) doesn't accept() the connections. The listen() is done using a small backlog (of 1). This test then does several connect() attempts and expects that the connect() attempts will accumulate in the pending queue and once the queue exceeds the backlog limit, then as specified in man listen: The backlog parameter defines the maximum length for the queue of pending connections. If a connection request arrives with the queue full, the client may receive an error with an indication of ECONNREFUSED. then the connect() attempt will receive a ECONNREFUSED. However, in macos 27, such a connect() attempt leads to ECONNRESET (Connection reset by peer) instead of ECONNREFUSED. Is this expected? Experiments show that prior versions of macos were returning a ETIMEDOUT for such connect() attempts. If this new error is expected from connect() when the backlog limit has exceeded, should it be specified in the man listen documentation? Rename the attached main.c.txt to main.c. Compiling the attached program on macos 27, using clang main.c and then running ./a.out results in: ----------------------- MacOS version: 27.0.1 Kernel version: Darwin Kernel Version 27.0.0: Tue Aug 11 21:02:16 PDT 2026; root:xnu-13432.1.9~1/RELEASE_ARM64_T8112 ----------------------- started server at at 127.0.0.1:52753 with a backlog of 1 connect() attempt 1 - connected connect() attempt 2 - connected connect() attempt 3 - connected connect() attempt 4 - connected connect() attempt 5 - failed to connect() - Connection reset by peer <-- FAILURE: Unexpected error code, expected either ETIMEDOUT or ECONNREFUSED but got 54 connect() attempt 6 - connected connect() attempt 7 - connected connect() attempt 8 - connected connect() attempt 9 - failed to connect() - Connection reset by peer <-- FAILURE: Unexpected error code, expected either ETIMEDOUT or ECONNREFUSED but got 54 connect() attempt 10 - failed to connect() - Connection reset by peer <-- FAILURE: Unexpected error code, expected either ETIMEDOUT or ECONNREFUSED but got 54 connect() attempt 11 - failed to connect() - Connection reset by peer <-- FAILURE: Unexpected error code, expected either ETIMEDOUT or ECONNREFUSED but got 54 On a related note, it's unclear why several of the connect() attempts succeeded instead of just 1 of them succeeding. On prior versions of macos, the output of the same program is: ----------------------- MacOS version: 26.7.1 Kernel version: Darwin Kernel Version 25.6.0: Tue Aug 18 17:49:13 PDT 2026; root:xnu-12377.161.15.700.19~2/RELEASE_ARM64_T6000 ----------------------- started server at at 127.0.0.1:52451 with a backlog of 1 connect() attempt 1 - connected connect() attempt 2 - failed to connect() - Operation timed out connect() attempt 3 - failed to connect() - Operation timed out connect() attempt 4 - failed to connect() - Operation timed out connect() attempt 5 - failed to connect() - Operation timed out connect() attempt 6 - failed to connect() - Operation timed out connect() attempt 7 - failed to connect() - Operation timed out connect() attempt 8 - failed to connect() - Operation timed out connect() attempt 9 - failed to connect() - Operation timed out connect() attempt 10 - failed to connect() - Operation timed out connect() attempt 11 - failed to connect() - Operation timed out and this output is much more understandable and deterministic. main.c.txt
2
0
113
2d
Does SessionGetInfo provide authoritative current-session liveness for an ASID from a Mach audit token?
Environment: macOS 26.6.2 (25G83) Xcode 26.6 (17F113) macOS command-line process Security.framework SessionGetInfo ASID obtained from the kernel-provided audit token in a received Mach message I’m implementing a security-sensitive Mach IPC receiver. The receiver obtains the sender’s audit token from the Mach message trailer and derives the sender PID, effective UID, and audit session ID (ASID). The sender executable identity is validated separately. Given the ASID, SessionGetInfo can successfully return the corresponding SecuritySessionId and session attributes. The question is about the freshness and synchronization semantics of that lookup. At the point where the receiver authorizes a request, can a successful SessionGetInfo(asid, ...) result be treated as authoritative evidence that the corresponding login/audit session is still currently valid? In particular: What happens if the session logs out, terminates, or is revoked concurrently with the lookup? Can SessionGetInfo successfully return information for a session that is no longer current due to caching or propagation delay? Are there documented ordering or synchronization guarantees between session termination and subsequent SessionGetInfo calls from another process? Can the lookup block for an unbounded period if the underlying security service is unavailable? Is there a supported timeout or cancellation mechanism? Is there another supported public macOS API better suited to establishing authoritative current-session liveness for an ASID obtained from an audit token? The security requirement is fail-closed. I’m specifically trying to avoid private APIs, process-table heuristics, diagnostic launchctl output, or assumptions that the ASID encoded in a previously received audit token necessarily represents current session state. If the public API does not provide an authoritative liveness/freshness guarantee, confirmation of that limitation would also answer the design question. I also have a minimal 122-line Xcode sample that: creates and receives a Mach message, reads the kernel-provided audit trailer, extracts the ASID, calls SessionGetInfo, and prints the returned session ID and attributes. I can provide the sample project if useful.
3
0
105
2d
VZVirtualMachineView.automaticallyReconfiguresDisplay does not work for Golden Gate
I am using Virtualization framework for running Golden Gate VM in swift ui window with VZVirtualMachineView. i have set the automaticallyReconfiguresDisplay to true. but when i resize the window the resolution of Golden Gate does not change automatically to fit the window. This works fine for Tahoe. Golden Gate is not respecting the automaticallyReconfiguresDisplay. Any help in fixing this bug would be very helpful to me. Thanks in advance
4
0
732
2d
Custom SwiftData DataStore
In the sample code below I am reading and writing ProductRecord model objects to PostgreSQL using a custom DataStore. However it is unclear to me how I can set this up such that I am able to also write other model object types to the same custom DataStore. Currently the ProductPostgresSnapshot is specific to the ProductRecord and the PostgresSwiftDataStore Snapshot refers to this ProductPostgresSnapshot. Any idea how I would change this to accommodate different model object types such as SupplierRecord ? Full console program shown below. Full console program
3
0
230
2d
iOS 27 CarPlay section headers disappear with detail text or images
Adding an image or detail text to a CPListSection makes the whole header disappear. With no detailText or headerImage With detailText or headerImage FB24061858 open but no response.
Replies
2
Boosts
2
Views
428
Activity
1d
In-App Purchases work in TestFlight but not during App Review
Hi everyone, I'm a new iOS developer, and my first app has been rejected twice because of In-App Purchase issues. Setup: Flutter, in_app_purchase 3.3.0, in_app_purchase_storekit 0.4.10 (StoreKit 1) One auto-renewable subscription and one non-consumable lifetime purchase Both products show "Ready for Review" in App Store Connect. Paid Apps Agreement is active. First review: The prices were visible on an iPad, but the subscription purchase failed (Guideline 2.1(b)). Second review: Neither product showed a price on an iPhone (Guideline 2.1(b)). Apple also noted missing subscription information (Guideline 3.1.2(c)). On my iPhone 15, both products load correctly and test purchases work in TestFlight using my regular Apple Account. Product IDs, pricing, availability, and localizations appear correct. My question: What could cause queryProductDetails / SKProductsRequest to return no products during App Review when everything works in TestFlight? Any suggestions would be greatly appreciated. Thanks! :)
Replies
0
Boosts
0
Views
129
Activity
1d
Logitech MX Brio 4K webcam detected but no video on macOS 27 Golden Gate (Mac Studio M4)
Since upgrading to macOS 27 Golden Gate, my Mac Studio (M4) recognises my Logitech MX Brio 4K webcam, but no video feed is displayed. The camera appears to be detected by the system, but the video signal does not show up in: FaceTime Photo Booth Logitech Options+ I've spent quite a bit of time troubleshooting the issue, including following diagnostic steps suggested by Siri and Copilot, but everything points to a potential macOS-related problem rather than a hardware or configuration issue. Has anyone else experienced this with the MX Brio or other webcams on macOS 27 Golden Gate? I reported the issue to Apple through the Feedback app when Beta 1 was released, but so far I haven't received a response or found a workaround. Any insights or suggestions would be greatly appreciated. Thanks!
Replies
2
Boosts
0
Views
113
Activity
1d
Can watchOS apps access Apple-generated sleep stages in real time for a smart alarm?
I’m evaluating a native watchOS smart-alarm app and would like to clarify whether public APIs support its core requirement before building a prototype. The app would wake the user during a 20–30-minute window before their selected alarm time, using Apple Watch’s own sleep-stage classifications available through HealthKit’s sleepAnalysis category: Core, Deep, REM, and Awake. I have reviewed HKCategoryValueSleepAnalysis, HKAnchoredObjectQuery, HKObserverQuery, background delivery, and WKExtendedRuntimeSession’s Smart Alarm mode. However, I haven’t found documentation establishing when Apple-generated sleep-stage samples become available during an ongoing sleep session. Could you clarify: Are Apple-generated sleep-stage samples written to the Watch’s local HealthKit store during sleep, or only after the sleep session ends or subsequent processing? If available during sleep, is there any documented update cadence or latency that would make them suitable for a smart alarm? Should the latest sample be treated only as a retrospective classification rather than the current sleep stage? Can an app query these samples during a Smart Alarm extended runtime session while the Watch is worn and unlocked, with its display off and Sleep Focus enabled? Are there relevant execution or data-access restrictions? If this use case is unsupported, is there any public API that exposes Apple’s current sleep-stage estimate? If not, which Feedback Assistant category is appropriate for requesting this capability? The intended approach queries HealthKit directly on Apple Watch, without depending on Watch-to-iPhone synchronization, and retains a fixed latest wake-up time as a fallback. This is an API feasibility question, not a reproduced bug. I haven’t yet built or tested a prototype. Thank you.
Replies
0
Boosts
0
Views
58
Activity
1d
MacOS HomeKit private (and still useable) application
How do I write a macOS (no need for i/Pad/OS at all) application which supports HomeKit for my own private use only? My original idea was simply to write it non-provisioned, which would solve all problems perfectly. Nevertheless, that, triple alas, seems not possible (https://developer.apple.com/forums/thread/849288). Provisioned one built locally has a lot of problems, among which there are e.g., big hurdles to run it at my other Macs (https://developer.apple.com/forums/thread/848903?answerId=907702022#907702022) an extremely limited expiration date A reasonable solution would be a creation of a provisioning profile which would include an expiration date in a far future and also IDs of my other computers; alas, far as I understand, this does not seem to be possible with a Personal Team, as detailed in https://developer.apple.com/forums/thread/848903?answerId=907568022#907568022. Whilst a sort of solution might be the nuclear one, it does not feel right the slightest — I need just to run my own app, nothing more, and whilst naturally I gladly accept all the possible dangers of code I wrote myself, I definitely would not want to get completely vulnerable where all the other apps (and other threats) in the world are concerned. I've checked also the Unlisted distribution; far as understand it properly, won't do either, e.g., since it will be declined ... if your app is in a beta or prerelease state — the application is fully intended to be used locally for months or even years in this state. Besides, even Unlisted apps must go through Review, and when I bump to a need to make any kind of change, I want simply do that locally and launch my new version immediately without any Review hassle. Also, in this case the otherwise important privacy issues like e.g., determining the proper computer name (https://developer.apple.com/forums/thread/813853?answerId=874075022#874075022) are of absolutely no importance. Are there other, more reasonable options? What's the proper solution, after all? Thanks!
Replies
0
Boosts
0
Views
117
Activity
2d
Cannot run Catalyst app on other devices?!?
I prepare a private project in Xcode, use Archive, Distribute/Copy, save the application somewhere. Copy it to my other computer, run. Works perfectly with normal MacOS applications. With Catalyst ones though it does not; whatever I try, all I get is “The application XXX cannot be opened”. What do I do wrong and how to fix the problem? Thanks!
Replies
8
Boosts
0
Views
253
Activity
2d
Apple Watch Ultra: Does an underwater compass app require the full Submerged Depth and Pressure entitlement to operate below 6 meters?
Hi there, I'm planning to develop a simple underwater compass app for Apple Watch Ultra 2, intended for recreational scuba diving down to 40 meters. The app itself does not need depth or pressure measurements beyond 6 meters. Its primary function is compass navigation using heading data. During a dive, however, I would like the app to: remain frontmost and visible throughout the dive; use Water Lock; use an underwater-depth WKExtendedRuntimeSession; continue receiving compass heading updates; allow interaction through physical controls such as the Digital Crown and Action Button; remain operational below 6 meters, potentially down to 40 meters. I understand that the Shallow Depth and Pressure capability limits CMWaterSubmersionManager depth/pressure data to approximately 6 meters, while access to depth/pressure data down to 40 meters requires the full Submerged Depth and Pressure entitlement. My question is: If my app does not require depth/pressure measurements beyond 6 meters, is the full Submerged Depth and Pressure entitlement still required simply to keep the underwater extended runtime session, UI, compass heading updates, and physical-control interaction working below 6 meters? In other words, does the 6-meter entitlement limit apply only to depth/pressure data, or does it also limit the ability of an underwater compass app to remain operational during a scuba dive below 6 meters? Target hardware: Apple Watch Ultra 2. Thanks in advance!
Replies
2
Boosts
0
Views
452
Activity
2d
What is the supported DriverKit Stop/drain sequence for an IOUserClient operation queue?
Environment: macOS 26.6.2 (25G83), Apple silicon Xcode 26.6 (17F113) DriverKit SDK 25.5 I am implementing a DriverKit IOService with an IOUserClient. This is a lifecycle and object-ownership question independent of the device protocol. The intended design admits at most one user client during a provider lifetime. Lifecycle methods run on the provider’s default queue, while IOUserClient ExternalMethod requests run on a separate serial IODispatchQueue. At most one device request may be in flight. The shutdown invariant we need is: Stop accepting new requests. Allow every accepted request to complete exactly once, or cancel it. Observe completion of the operation queue’s cancellation handler. Call the inherited Stop implementation last. Perform no provider access afterward. The relevant public documentation is: IOService::Stop: https://developer.apple.com/documentation/driverkit/ioservice/stop IODispatchQueue::Cancel: https://developer.apple.com/documentation/driverkit/iodispatchqueue/cancel IOService::SetDispatchQueue: https://developer.apple.com/documentation/driverkit/ioservice/setdispatchqueue For the normal path, the proposed sequence is conceptually: Stop(provider): close request admission operationQueue->Cancel(cancellationHandler) wait for the cancellation handler from the separate queue super::Stop(provider) I need clarification of the complete supported public API contract: If IODispatchQueue::Cancel returns a non-success result, is its cancellation handler still guaranteed to execute? If it is not, what supported action lets Stop keep the provider and user client valid until previously accepted work is no longer capable of accessing them? Is it supported for the provider and its one user client to share the provider-owned serial operation queue? If the IOUserClient stops independently, must it own and cancel a separate queue, or is there a supported per-client drain mechanism that does not cancel provider-owned work? Is the driver’s public IOService::Stop override guaranteed to run on every termination path where accepted user-client work must be drained, including when the provider is already inactive or the DriverKit server has slept? If not, which public lifecycle callback supplies that drain point? Is blocking the provider’s default queue inside Stop while awaiting the cancellation handler from a separate operation queue the supported interpretation of “wait for your cancellation handlers”? If not, what public continuation mechanism should be used before calling inherited Stop? We also observed one power-management panic after sleep/wake: HiMDScsiDriver::setPowerState(..., 0 -> 4) timed out after 20342 ms The DEXT does not currently override SetPowerState. This panic motivates the lifecycle review, but I am not treating it as proof that the Stop/drain design caused the timeout. I am looking specifically for a supported public DriverKit sequence. I do not want to rely on private framework entry points or infer object-lifetime guarantees from a successful build or experiment.
Replies
7
Boosts
0
Views
1.4k
Activity
2d
401 error registering sandbox domain with Web Merchant Registration API
Hi, We recently applied for the Web Merchant Registration API and created our platform integrator ID. I am trying to register a domain in sandbox with the API: POST https://apple-pay-gateway-cert.apple.com/paymentservices/registerMerchant Content-Type: application/json { "domainNames": ["<URL>"], "partnerInternalMerchantIdentifier": "<merchant_id>", "partnerMerchantName": "<merchant_name>", "encryptTo": "<platform_integrator_id>" } Client certificate is provided via curl --cert/--key; the TLS 1.3 handshake completes successfully — the server requests the client cert, our Certificate + CERT verify are accepted, and the connection is established. But the response is { "statusMessage": "Payment Services Exception Unauthorized", "statusCode": "401" } How do I go about debugging this?
Replies
0
Boosts
0
Views
281
Activity
2d
Iphone 14 pro cannot charge using mfi lightning otg after upgrading to ios 27
Hi, i am using mopai kt393 which is listed on apple mfi devices list in web. My phone is 14 pro(ios 27) and cannot be charged via mopai kt393. I tried to use another phones : 14 pro(ios 18), 13 basic(ios 26), they were charged normally. Is this a bug of ios27? or new rules on ios 27? or mopai kt393 is actually not a mfi device? Anyone has this issue too?
Replies
1
Boosts
0
Views
68
Activity
2d
CarPlay suppresses local notification sound app-wide — does a Live Activity alert behave differently?
I've confirmed through controlled testing that local notification sound is suppressed app-wide whenever CarPlay is connected, for an app with no CarPlay entitlement. Tested: Sound plays normally with CarPlay disconnected Sound is silent with CarPlay connected — confirmed by repeatedly connecting/disconnecting CarPlay with the identical notification, nothing else changed No difference with phone locked vs. unlocked No difference with Driving Focus on vs. off No difference with interruptionLevel set to .active vs. .timeSensitive Device: iPhone 13, iOS 26.6.2. Head unit: 2024 Toyota Tacoma (CarPlay). My app has no CarPlay entitlement (not navigation/audio/EV/parking/food- ordering), so I suspect this suppression may be intentional — but I can't find it documented anywhere. Given that, I'm looking at iOS 26 Live Activities as an alternative, since Apple's docs say a Live Activity can appear on the CarPlay Dashboard without a CarPlay entitlement. But I can't find documentation on: Whether a Live Activity push-to-start or update plays an audible sound when the phone is locked and CarPlay is connected. Whether Live Activity content backed by data-protection class A/B storage reliably renders in this state (separate widget guidance warns this "likely won't work in CarPlay" since phones are usually locked — unclear if this applies to ActivityKit content specifically). Has anyone tested this, or know if it's documented somewhere I'm missing? Trying to figure out if Live Activities are a viable path to a driver- audible alert for a non-CarPlay-entitled app, before I invest more engineering time in it.
Replies
0
Boosts
0
Views
114
Activity
2d
iPhone sync on MacOS Golden Gate 27.0.1 (26A434) caused data exposure out of sandbox
Hi guys, I connected iPhone using USB cable to Mac running Golden Gate 27.0.1 (26A434) and in Finder I selected iPhone to open sync page I was looking at Files tab and trying to get data from one of the apps. As I was doing that at certain point after disconnecting and connecting USB cable I wanted to avoid sync, so when dialog "Trust this computer" showed up on iPhone, I tapped "Cancel". Then when disconnecting cable and connecting again, it started sync and under Files under the app in treeview original data disappeared (a database file and 2 folders with images) and iTunes_Control and Recordings folders showed up instead. I copied these folders to my Mac and there were files containing data. It looks like instead of Documents folder belonging to the app the sync mapped completely different storage location, which should have been protected by sandbox (I'm assuming). I clicked "Eject" icon in Finder, disconnected cable, connected again and it started sync, but ultimately failed with an error that some file does not exist. That dialog presented title with a completely different name than is the name of my iPhone, it presented something like Robert's iPhone, which is a name usually chosen by default when setting up new iPhone. I tried sync 3 times, but nothing helped to fix the problem. Has anyone seen this issue? I completely shutdown iPhone and started again. Sync completed successfully and under that app its original data showed up again (database file and 2 folder with images), iTunes_Control and Recordings folders didn't show up. Is it possible that sync mounted wrong location and exposed data that should have been protected by sandbox and never exposed this way and under wrong app?
Replies
0
Boosts
0
Views
147
Activity
2d
macOS guest freezes after update reboot on M4 host with Virtualization.framework
macOS guest (Virtualization.framework) freezes with all vCPUs halted right after a macOS update reboot - 3/3 on a macOS 26.7.1 (25G309) M4 host, seen with both UTM and Parallels Summary On a macOS 26.7.1 (25G309, beta/seed build) host with an Apple M4, every macOS guest that runs an in-place macOS update freezes at the same point: the in-OS phase of the update completes and reports success, the guest requests a reboot, records a shutdown stall 9 seconds later, reboots twice, shows the update progress screen for about a minute, and then stops. All four vCPUs enter WFI and never wake, paravirtualized graphics stops submitting, no I/O is pending on the host side, and no host service logs an error. The VM never recovers and has to be killed. Reproduced 3 out of 3 times, under two different front-ends (UTM and Parallels Desktop) and two guest versions (15.7.x and 26.6.2). Environment Host: iMac (Mac16,3), Apple M4, 16 GB RAM, macOS 26.7.1 build 25G309 (seed channel), installed the evening before the first failure. Primary guest: macOS 15.7.9 (24G830), hardware model VirtualMac2,1, 4 vCPUs, 6 GB RAM, 90 GB raw disk image (virtio-blk) stored on an external USB SSD. Networking bridged to the built-in Ethernet port. Devices enabled: memory balloon, audio, entropy, clipboard sharing; display 1920x1200 with dynamic resolution. Front-end for the primary case: UTM [version], Apple Virtualization backend. Guest was the only VM running, cold-booted, window open. Update being applied: MSU_UPDATE_24H23_patch_15.8_minor (15.7.9 -> 15.8). Other cases: a macOS 26.6.2 guest under UTM; a macOS 15.7.7 -> 15.8 guest under Parallels Desktop 26.4.2 (57518). Steps to reproduce Cold-boot a macOS 15.7.9 guest under Virtualization.framework, as the only VM on the host. In the guest: System Settings > Software Update > install macOS 15.8. Let it reboot. Expected The guest installs the update and boots into 15.8. Actual — timeline of the primary case (R = the moment Software Update requested the reboot; absolute timestamps are in the attached logs) R-23 min to R-5 min: UpdateBrainService prepares the update inside the guest, writing about 25 GB (two "disk writes" resource reports: 16.5 GB then 8.5 GB). No errors. R-1:56: post-logout install configured; disk space check passes (5.7 GB required, 40.7 GB free). R-1:44: "SUOSUPostLogoutInstallOperation: Applying MSU update". R: "Applied MSU update"; FileVault stash committed ("kAppleFDEKeyStore_commitStash success"); "Rebooting (success = 1, displayAsleep = 0, shutdown = 0)". This is the last line the guest ever writes to install.log. R+9 s: the guest writes a shutdown_stall diagnostic report. R+10 s: host sees ParavirtualizedGraphics "Device reset" / "PGDisplayNub[0]: Destroyed" (reboot #1). R+1:20: second device reset (reboot #2), 70 s after the first. On the host, the vmnet interface is torn down and recreated with no error, the AppleVirtualPlatformIdentity service completes boot attestation with no error, and the guest's graphics driver renegotiates ("Guest requested binary version: 209"). R+1:38: host logs "PGDisplay[0]: Change display mode to 3606x2254" — the guest is on the update progress screen. R+1:41 to R+2:25: the guest's six PGFifoThreads go idle one at a time. The progress bar stops partway. No further activity of any kind. R+11:35: spindump of the VM host process (com.apple.Virtualization.VirtualMachine): 0.042 s of CPU over a 5 s sample all four com.apple.virtualization.thread.cpu-N threads in Hv::Vcpu::run() -> HvCore::Hypervisor::VcpuStateManager::wait_for_interrupt() -> __psynch_cvwait cpu-0/cpu-1 wake on a ~20 ms timer tick and return to WFI; cpu-2/cpu-3 had not run for seconds no thread in any file read, write or fsync (no host I/O outstanding) PGFifoThreads last ran 550–614 s earlier process state Ss (sleeping), not U Host kernel log for the window: no USB, APFS, I/O error, timeout or reset entries. No hardware video decoder (AppleAVD) errors. The VM was left for over an hour with no change, then killed. Second case (same host, same day, UTM, guest macOS 26.6.2) Identical signature: two graphics device resets 69 s apart, display mode set 3 s after the second one, last graphics activity about a second later, then all vCPUs idle in WFI for ~6.5 hours until the VM was killed. Third case (same host, same day, Parallels Desktop 26.4.2, guest 15.7.7 -> 15.8) The guest was suspended in the middle of its update and resumed later. On resume ("-[_PGDevice willResumeWithSuspendState:error:]: Begin resume", preceded by "[VirtualMachineParameterBuilder] Failed to get auxiliary file identifier"), paravirtualized graphics never came back — its FIFO threads ran once and never again — and the guest's vCPUs sat in WFI. This may be a separate save/restore defect, but the end state is the same. What I believe is ruled out The in-OS phase of the update: it completed and reported success. Guest kernel panic: vCPUs are halted, not spinning, and there is no panic report on the guest's data volume. Disk space: 40.7 GB free in the guest at install time. Host storage stall: no uninterruptible wait, no I/O frames in the spindump, no kernel storage errors. Host hardware video decoder: no AppleAVD errors in the primary case. Host services: vmnet and AppleVirtualPlatformIdentity completed normally seconds before the hang. Guest memory: 6 GB allocated. Not yet isolated The VM images live on an external USB SSD; not yet reproduced from internal storage. The memory balloon, audio and clipboard-sharing devices were enabled; not yet reproduced with them disabled. A third-party VPN client was running on the host (guest networking is bridged, so guest traffic bypasses the host tunnel, but host firewall rules could still affect bridged frames). I don't have a confirmed-good in-place guest update on this machine from before 26.7.1, so I can't state with certainty that this is a regression. Frequency 3 of 3 attempts on this host. Attachments / available on request spindumps of the hung VM host process (primary case and second case) host unified-log excerpts for both hang windows the guest's full install.log the guest's shutdown_stall report and the two UpdateBrainService disk-writes reports sysdiagnose captured while hung, if obtained Has anyone seen macOS guests stop at this point on the 26.7.x seeds? If you can reproduce, your host build, hypervisor, and whether the VM image is on internal or external storage would be useful to compare.
Replies
4
Boosts
3
Views
314
Activity
2d
IPSW for 15.7.7 missing
Hi, we're only seeing 15.6.1 IPSW available for VMs. Where can we find latest and secure versions of macOS IPSW on https://updates.cdn-apple.com/*/fullrestores/ ? Is there an official list somewhere that Apple provides? We need to be sure we can create the latest 15.7.7 VMs with automation and not rely on inner VM upgrades of MacOS.
Replies
4
Boosts
0
Views
246
Activity
2d
Is there any official way for a Screen Time app outside the EU to access per-app usage data?
I'm developing a digital wellbeing app using FamilyControls and DeviceActivity. The core functionality of the app is to show the user their per-application Screen Time usage, including the application identity and duration (for example, Instagram — 1h 30m, YouTube — 45m). I understand that on iOS 26.4+, AuthorizationStatus.approvedWithDataAccess and DeviceActivityData.activityData(filteredBy:using:) provide access to non-tokenized application usage data. I also understand the current Apple documentation states that customer installations can only obtain approvedWithDataAccess on devices located in the EU with an Apple Account configured to an EU country or region, and that outside the EU the authorization status never becomes approvedWithDataAccess. My app and test device are based in Kazakhstan. My question is not about bypassing Apple's privacy model or implementing an undocumented workaround. I would like to know whether there is any official path for a legitimate third-party Screen Time / digital wellbeing app to obtain this data outside the EU, for example: an additional entitlement; a developer approval or application process; a regional exception; an alternative Apple-supported API; or any other official mechanism. We already have the Family Controls distribution entitlement approved and have enabled the Family Controls App and Website Usage capability. If no such mechanism exists, I would appreciate confirmation that the EU restriction is currently absolute for customer installations and that there is no additional entitlement or approval process available for developers outside the EU. The reason I am asking is that per-application usage is a core part of the application's functionality, so I want to make sure I am not missing an official Apple-supported option before designing around this limitation.
Replies
0
Boosts
0
Views
79
Activity
2d
macos 27 - EDOM error from setsockopt() for SO_LINGER socket option for values greater than 32767
On macos 27, there appears to be a change in the setsockopt() implementation for the SO_LINGER option. It looks like the implementation now imposes a different maximum limit on the value that is accepted for linger. Consider the trivial attached C program. Rename it from main.c.txt to main.c. Compiling it (using clang main.c) and running it (using ./a.out), on older versions of macos (like 26.x), it returns: ----------------------- MacOS version: 26.7.1 Kernel version: Darwin Kernel Version 25.6.0: Tue Aug 18 17:49:13 PDT 2026; root:xnu-12377.161.15.700.19~2/RELEASE_ARM64_T6000 ----------------------- SUCCESS - set SO_LINGER to value 10 SUCCESS - set SO_LINGER to value 42 SUCCESS - set SO_LINGER to value 1024 SUCCESS - set SO_LINGER to value 32767 SUCCESS - set SO_LINGER to value 32768 SUCCESS - set SO_LINGER to value 65535 SUCCESS - set SO_LINGER to value 65536 SUCCESS - set SO_LINGER to value 65578 However, on macos 27, this now fails with EDOM error ("Numerical argument out of domain") for values greater than 32767: ----------------------- MacOS version: 27.0.1 Kernel version: Darwin Kernel Version 27.0.0: Tue Aug 11 21:02:16 PDT 2026; root:xnu-13432.1.9~1/RELEASE_ARM64_T8112 ----------------------- SUCCESS - set SO_LINGER to value 10 SUCCESS - set SO_LINGER to value 42 SUCCESS - set SO_LINGER to value 1024 SUCCESS - set SO_LINGER to value 32767 FAILURE - failed to set SO_LINGER to value 32768, reason: Numerical argument out of domain FAILURE - failed to set SO_LINGER to value 65535, reason: Numerical argument out of domain FAILURE - failed to set SO_LINGER to value 65536, reason: Numerical argument out of domain FAILURE - failed to set SO_LINGER to value 65578, reason: Numerical argument out of domain I'm guessing this is an intentional change, but I wanted to confirm nonetheless. Should the documentation of SO_LINGER and SO_LINGER_SEC socket options, in man setsockopt, mention the acceptable value range for them? main.c.txt
Replies
2
Boosts
0
Views
113
Activity
2d
macos 27 - unexpected/new errno from BSD socket connect() when pending connections exceed backlog
Please consider the trivial C program attached to this thread. The code creates a socket() and listen()s for connections, but (intentionally) doesn't accept() the connections. The listen() is done using a small backlog (of 1). This test then does several connect() attempts and expects that the connect() attempts will accumulate in the pending queue and once the queue exceeds the backlog limit, then as specified in man listen: The backlog parameter defines the maximum length for the queue of pending connections. If a connection request arrives with the queue full, the client may receive an error with an indication of ECONNREFUSED. then the connect() attempt will receive a ECONNREFUSED. However, in macos 27, such a connect() attempt leads to ECONNRESET (Connection reset by peer) instead of ECONNREFUSED. Is this expected? Experiments show that prior versions of macos were returning a ETIMEDOUT for such connect() attempts. If this new error is expected from connect() when the backlog limit has exceeded, should it be specified in the man listen documentation? Rename the attached main.c.txt to main.c. Compiling the attached program on macos 27, using clang main.c and then running ./a.out results in: ----------------------- MacOS version: 27.0.1 Kernel version: Darwin Kernel Version 27.0.0: Tue Aug 11 21:02:16 PDT 2026; root:xnu-13432.1.9~1/RELEASE_ARM64_T8112 ----------------------- started server at at 127.0.0.1:52753 with a backlog of 1 connect() attempt 1 - connected connect() attempt 2 - connected connect() attempt 3 - connected connect() attempt 4 - connected connect() attempt 5 - failed to connect() - Connection reset by peer <-- FAILURE: Unexpected error code, expected either ETIMEDOUT or ECONNREFUSED but got 54 connect() attempt 6 - connected connect() attempt 7 - connected connect() attempt 8 - connected connect() attempt 9 - failed to connect() - Connection reset by peer <-- FAILURE: Unexpected error code, expected either ETIMEDOUT or ECONNREFUSED but got 54 connect() attempt 10 - failed to connect() - Connection reset by peer <-- FAILURE: Unexpected error code, expected either ETIMEDOUT or ECONNREFUSED but got 54 connect() attempt 11 - failed to connect() - Connection reset by peer <-- FAILURE: Unexpected error code, expected either ETIMEDOUT or ECONNREFUSED but got 54 On a related note, it's unclear why several of the connect() attempts succeeded instead of just 1 of them succeeding. On prior versions of macos, the output of the same program is: ----------------------- MacOS version: 26.7.1 Kernel version: Darwin Kernel Version 25.6.0: Tue Aug 18 17:49:13 PDT 2026; root:xnu-12377.161.15.700.19~2/RELEASE_ARM64_T6000 ----------------------- started server at at 127.0.0.1:52451 with a backlog of 1 connect() attempt 1 - connected connect() attempt 2 - failed to connect() - Operation timed out connect() attempt 3 - failed to connect() - Operation timed out connect() attempt 4 - failed to connect() - Operation timed out connect() attempt 5 - failed to connect() - Operation timed out connect() attempt 6 - failed to connect() - Operation timed out connect() attempt 7 - failed to connect() - Operation timed out connect() attempt 8 - failed to connect() - Operation timed out connect() attempt 9 - failed to connect() - Operation timed out connect() attempt 10 - failed to connect() - Operation timed out connect() attempt 11 - failed to connect() - Operation timed out and this output is much more understandable and deterministic. main.c.txt
Replies
2
Boosts
0
Views
113
Activity
2d
Does SessionGetInfo provide authoritative current-session liveness for an ASID from a Mach audit token?
Environment: macOS 26.6.2 (25G83) Xcode 26.6 (17F113) macOS command-line process Security.framework SessionGetInfo ASID obtained from the kernel-provided audit token in a received Mach message I’m implementing a security-sensitive Mach IPC receiver. The receiver obtains the sender’s audit token from the Mach message trailer and derives the sender PID, effective UID, and audit session ID (ASID). The sender executable identity is validated separately. Given the ASID, SessionGetInfo can successfully return the corresponding SecuritySessionId and session attributes. The question is about the freshness and synchronization semantics of that lookup. At the point where the receiver authorizes a request, can a successful SessionGetInfo(asid, ...) result be treated as authoritative evidence that the corresponding login/audit session is still currently valid? In particular: What happens if the session logs out, terminates, or is revoked concurrently with the lookup? Can SessionGetInfo successfully return information for a session that is no longer current due to caching or propagation delay? Are there documented ordering or synchronization guarantees between session termination and subsequent SessionGetInfo calls from another process? Can the lookup block for an unbounded period if the underlying security service is unavailable? Is there a supported timeout or cancellation mechanism? Is there another supported public macOS API better suited to establishing authoritative current-session liveness for an ASID obtained from an audit token? The security requirement is fail-closed. I’m specifically trying to avoid private APIs, process-table heuristics, diagnostic launchctl output, or assumptions that the ASID encoded in a previously received audit token necessarily represents current session state. If the public API does not provide an authoritative liveness/freshness guarantee, confirmation of that limitation would also answer the design question. I also have a minimal 122-line Xcode sample that: creates and receives a Mach message, reads the kernel-provided audit trailer, extracts the ASID, calls SessionGetInfo, and prints the returned session ID and attributes. I can provide the sample project if useful.
Replies
3
Boosts
0
Views
105
Activity
2d
VZVirtualMachineView.automaticallyReconfiguresDisplay does not work for Golden Gate
I am using Virtualization framework for running Golden Gate VM in swift ui window with VZVirtualMachineView. i have set the automaticallyReconfiguresDisplay to true. but when i resize the window the resolution of Golden Gate does not change automatically to fit the window. This works fine for Tahoe. Golden Gate is not respecting the automaticallyReconfiguresDisplay. Any help in fixing this bug would be very helpful to me. Thanks in advance
Replies
4
Boosts
0
Views
732
Activity
2d
Custom SwiftData DataStore
In the sample code below I am reading and writing ProductRecord model objects to PostgreSQL using a custom DataStore. However it is unclear to me how I can set this up such that I am able to also write other model object types to the same custom DataStore. Currently the ProductPostgresSnapshot is specific to the ProductRecord and the PostgresSwiftDataStore Snapshot refers to this ProductPostgresSnapshot. Any idea how I would change this to accommodate different model object types such as SupplierRecord ? Full console program shown below. Full console program
Replies
3
Boosts
0
Views
230
Activity
2d