Posts under App & System Services topic

Post

Replies

Boosts

Views

Activity

Virtualization.framework VM execution ownership and crash reclamation on Intel macOS Monterey
Subject: Virtualization.framework VM execution ownership and crash reclamation on Intel macOS Monterey Hello, I’m investigating the lifecycle guarantees of Virtualization.framework on Intel macOS Monterey 12.7.x. The specific scenario is a VZVirtualMachine running a Linux guest. I need to understand the ownership and reclamation behavior when the process holding the VZVirtualMachine is abruptly terminated without calling stop() or performing normal cleanup. The key questions are: For a specific VZVirtualMachine on Intel macOS Monterey, which userspace task/process actually owns the Hypervisor VM and the vCPU threads backing guest execution? Is Hypervisor execution owned directly by the calling process, or by a separate process such as: com.apple.Virtualization.VirtualMachine or another Virtualization.framework backend? If the process holding the VZVirtualMachine is terminated with SIGKILL or crashes without executing cleanup code, is the underlying guest execution context necessarily destroyed? More specifically: Can guest vCPU execution continue after the client process has died? If a separate backend process owns the VM, is that backend guaranteed to terminate or destroy the VM when the client dies? Does this behavior apply to Intel macOS Monterey 12.7.x, or only to newer macOS releases? Is there a supported diagnostic on Monterey that can map one specific VZVirtualMachine instance to the task/process that actually owns its Hypervisor VM/vCPU execution? For example, would a diagnostic showing Hypervisor execution frames such as hv_vcpu_run in a process, combined with a reliable process-exit notification, be sufficient to establish that ownership relationship? If the Virtualization backend can survive the client process, what supported VM-specific recovery or termination mechanism is available to another process? The security property I need to establish is intentionally narrow: If the userspace owner of a VM is abruptly destroyed, guest computation must not be able to continue indefinitely as an independent execution domain. Persistent disk files or other inert VM artifacts are not the concern; the question is specifically about live guest/vCPU execution and its ownership lifecycle. I’m looking for the supported architectural contract or diagnostic approach, not undocumented implementation details. Target environment: macOS Monterey 12.7.x Intel x86_64 Virtualization.framework Hypervisor.framework Hardware virtualization available No private APIs or privileged/kernel extensions Thank you.
6
0
449
4d
Enrolment problems
Im trying to enrol on apple developer program for last couple of years and its always failing with first click and saying cannot be created at this time i. i tried to open many cases with apple and no feedback . any solution .
0
0
78
4d
How can a CarPlay voice-based conversational app let the car show and control an active conversation?
We make Alchemy, a leadership coaching app on the App Store. In Alchemy hands-free mode, a person talks with their coach out loud. It is a live, two-way voice conversation over the internet, started from a button in the app. Many of our users do this while out for a walk and especially while driving. Here is how it looks on Audroid Auto : We have requested the CarPlay voice-based conversation entitlement (com.apple.developer.carplay-voice-based-conversation) and plan to build the CarPlay screen with CPVoiceControlTemplate. Question: for an app with this entitlement, what is the supported way to let the car know that a conversation is active, so that the car can show it on its own displays (for example a name or title in the instrument cluster) and the driver can pause or end it with the steering wheel controls? What we want. On an Android phone connected to the same car (an Audi with a digital instrument cluster), our voice conversation appears in the cluster's header as an active call with a name, and the steering wheel button ends it. We would like the same for iPhone users, using the APIs Apple intends. What we tried. iPhone 13, iOS 27.2 beta, wired CarPlay, same car: We started the conversation as an outgoing CallKit call (CXStartCallAction, generic handle, localizedCallerName set), with the audio background modes. The phone showed a call. The instrument cluster did not change, and the CarPlay Phone screen showed nothing. With the audio background mode only, the conversation works well through the car speakers and microphone, on the Home Screen and with the phone locked. The instrument cluster stays on the radio station, and CarPlay shows only the orange microphone indicator. If the car's own displays cannot show a voice-based conversational app's session, that is a useful answer too. In that case, what can the Voice Control template show the driver, and can the steering wheel controls act on the conversation at all? The goal is truly hands free so nobody gets a ticket while getting coaching help. 👍 Thank you.
0
0
64
4d
Kernel panic "m->m_flags & M_PKTHDR" in uipc_mbuf.c on SMB clients over 10 GbE (macOS 26)
We have a group of Macs that mount SMB shares over 10 GbE with jumbo frames (MTU 9000). Since late June, they have been kernel panicking several times a day with the same assertion: panic(cpu N caller ...): assertion failed: m->m_flags & M_PKTHDR, file: .../xnu/bsd/kern/uipc_mbuf.c, line: 4839 @uipc_socket.c:8260 Panicked thread: dlil_input_en0 Last started kext: com.apple.filesystems.smbfs 6.0.1 Environment Clients: Mac Studio (M1 Max and M1 Ultra) and Mac Pro (2019, Intel with T2), using the built-in 10GBASE-T at MTU 9000 macOS 26.5.1 (25F80), 26.6.2 (25G83) and 26.7 (25G229); it panics on all three Servers: Samba-based NAS, SMB 3.1.1, signing on, encryption off Filed as FB24912731 What we've found It still panics with our third-party EDR fully uninstalled. The Mac that panics needs an active SMB session. A Mac left on the network without a share mounted stayed up through several events that took down the others. Panics are often simultaneous across machines: two to six Macs, with different hardware and different macOS builds, within the same minute. It doesn't need sustained heavy throughput. Some panics came within minutes of reconnecting, during light editing. Setting kern.skywalk.flowswitch.rx_agg_tcp_host=0 did not help. The switch and server links stay up, and spanning tree doesn't change during these events. Only the Macs' ports drop. In one server-side capture, the client stopped sending within about 0.2 ms of receiving a READ response made of 8948-byte frames. That fits the panicked thread being dlil_input. Two existing threads look related Kernel panic using Vagrant synced folders via NFS beginning with macOS 15.4 (FB17853906). A DTS reply there said the issue is in kernel mbuf management and that SMB "is very likely to experience a similar panic." Incorrect packet handling in SMBClient MacOS 26, which describes a race in SMBClient under heavy load above about 10 Gbps. Questions Is this the same underlying issue as FB17853906, and is a fix planned for macOS 26? Our 2019 Mac Pros can't move to a later major release. Is there a known workaround, such as a sysctl, an nsmb.conf option, or a change to MTU or offload settings? Is there logging or a diagnostic we can leave enabled to capture more state at panic time? We can't reproduce this on demand, but between several machines we see it multiple times a day. We can provide full panic reports, sysdiagnoses, and packet captures from both client and server sides.
6
0
465
4d
Access to Matter “characteristic” in a HomeKit app?
Hi there, I am working on a (Mac Catalyst) HomeKit my own private application, which observes different characteristics of different accessories. This works (also thanks to the advice here, thanks again to all who helped!) like a charm. Now I've found that one of my outlets which is connected through Matter supports power consumption (in Home.app), but there is no characteristic for that, all I can see is its power state. Self-evidently, access to the consumption would be something Matter-specific. At this moment, to save time, I'd rather not study the complete Matter kit in detail if it can be dodged for this particular very limited goal. Is it possible just as simply as possible to read in (if readable) and observe (if observable) those extra Matter characteristics (if any) for an HMAccessory, presumably through its matterNodeID somehow? I'd be grateful for a sample code, if some is available (preferably ObjC, but of course Swift better'n nothing). Thanks a lot!
5
0
129
4d
Family Controls / DeviceActivity: Can an on-device usage result be shared as an abstract score or goal-completion event?
I’m evaluating an iOS app that uses Family Controls / DeviceActivity for an adult user’s voluntary personal device-management and digital-wellbeing goals. The app would also have an optional social competition feature where friends participate in fantasy-style leagues based on completion of their individual digital-wellbeing goals. I’m trying to understand the restrictions in Apple Developer Program License Agreement Section 3.3.3(P), specifically whether a privacy-preserving result derived locally from Family Controls / DeviceActivity can leave the device when the underlying usage data never does. I’m considering three architectures: A — Locally derived fantasy score DeviceActivity information is evaluated entirely on-device and converted locally into an abstract score. The server receives only: fantasy_points = 82 No Screen Time duration, app identity, website activity, bundle identifier, or underlying usage information leaves the device. B — Binary goal completion A user creates a private usage goal, such as remaining below their chosen daily device-usage threshold. The goal is evaluated entirely on-device. The server receives only: goal_completed = true The server then awards predetermined fantasy points. It never receives the underlying Screen Time value. C — Opaque challenge completion A user privately selects an app/activity goal. DeviceActivity evaluates the threshold locally. The server receives only: challenge_id = C928 completed = true The server knows C928 is worth a predetermined number of points, but does not receive the selected app identity, usage duration, Screen Time quantity, or other underlying DeviceActivity information. In all three approaches, raw Screen Time duration, per-app usage duration, application/bundle identity, website activity, DeviceActivity reports, and underlying historical usage records would remain on-device. Friends would only see fantasy points, matchup results, standings, and/or achievements. My question: Under Section 3.3.3(P) and the Family Controls requirements, are any of A, B, or C permitted? More specifically, does Apple consider an abstract score, boolean goal-completion result, or opaque challenge-completion result to itself be “device or usage data” when it was derived from Family Controls / DeviceActivity? If none of these architectures are permitted, is there a supported privacy-preserving architecture that allows an on-device DeviceActivity evaluation to affect a server-side social or multiplayer feature without transmitting the underlying device/usage information? I’m trying to establish the compliant architecture before development rather than build around an incorrect interpretation of the Family Controls requirements.
0
0
269
4d
Supported way to test Family Controls .child authorization without using a child's personal account?
I'm developing an iOS parent-child app that uses FamilyControls and DeviceActivity. Before distribution, I need to test AuthorizationCenter.shared.requestAuthorization(for: .child), including the guardian approval flow. So far I have tested .individual, which authenticates the device owner and does not exercise the child flow. Apple Developer Program Support directed me to this forum. What is the Apple-supported way to test this flow in this situation? Is there an Apple-supported test-only account or setup for this flow without using a child's personal Apple Account? If so, where are its requirements documented? If not, what is the recommended alternative? Can Sandbox Apple Accounts used for StoreKit Family Sharing tests be used to sign in to iCloud and test FamilyControls .child, or are they limited to purchase testing? Is there a supported simulator or other test method for guardian approval, or must this be verified using a child Apple Account in a real Family Sharing group on physical devices? I want to follow Apple's account rules and test the actual parental authorization path before distribution. References to official guidance would be appreciated.
0
0
65
4d
Apple Pay merchant domain verification fails despite valid TLS configuration
We are unable to verify our Apple Pay merchant domains. Apple Developer Portal returns: “Domain verification failed. Review your TLS Certificate configuration to confirm that the certificate is accessible and a supported TLS Cipher Suite is used.” We have confirmed that the verification endpoints are publicly accessible, return HTTP 200, and support TLS 1.2/1.3 with valid certificates and supported cipher suites. The domains are behind Cloudflare. However, when verification is triggered, we do not see an HTTP request from Apple in our Cloudflare request logs. Has anyone experienced a similar issue with Apple Pay merchant domain verification, especially with domains behind Cloudflare? We have also submitted a report through Feedback Assistant.
0
0
81
4d
CloudKit container data disappeared.
Most of my CloudKit data has been missing from my container for over a week. No response from Apple support. I am very worried it may be unrecoverable.my apps can not access the data and the dashboard shows a huge amount of files and data in other files missing. These are needed to operate our chiropractic clinic and contain patient and transaction history. This might be a disaster for us.
4
0
588
4d
Bug in Accelerate Lapack - Wrong eigenvectors
In the LAPACK interface of Accelerate (the default, without ACCELERATE_NEW_LAPACK), zheev with JOBZ='V', UPLO='U' returns eigenvectors that are neither orthonormal nor eigenvectors, while INFO=0. The eigenvalues are correct. zhegv with UPLO='U' fails the same way (tested with B = identity). It happens when: the matrix is complex Hermitian of order N >= 130 (N = 129 is correct, N = 130 already fails, N = 300 fails), and its last two or more rows and columns are exactly zero (one zero row is fine). Zero rows at the start or in the middle are fine. Banded and dense matrices both fail. On the same matrices the following are correct to rounding (1e-15): zheev and zhegv with UPLO='L', zheevd with UPLO='U', dsyev with UPLO='U' on real symmetric matrices of the same shape, zheev with UPLO='U' through the new LAPACK interface (-DACCELERATE_NEW_LAPACK). Since only the eigenvectors are wrong, and only above N=129 (presumably where zhetrd switches to its blocked code), the fault seems to be in the blocked Householder reduction or in the back-transformation (zhetrd/zlatrd or zungtr/zungql) of the legacy library, for columns that are zero. Asking LAPACK for the optimal LWORK (LWORK = -1 query) does not change the result. We found this in a physics code (Quanty, quanty.org), where a matrix of this shape arises naturally: a block tridiagonal (block Lanczos) matrix whose last block is padded with zeros after deflation. The wrong eigenvectors silently degraded results by 1e-4 relative, instead of 1e-15. STEPS TO REPRODUCE Save the attached zheev_upper_bug.c. clang -O2 zheev_upper_bug.c -o zheev_upper_bug -framework Accelerate ./zheev_upper_bug For comparison: clang -O2 -DACCELERATE_NEW_LAPACK zheev_upper_bug.c -o zheev_upper_bug_new -framework Accelerate && ./zheev_upper_bug_new The program builds a random Hermitian matrix (fixed seed, entries in [-0.5,0.5), bandwidth 11 or dense), zeroes its last NZERO rows and columns, calls zheev/zhegv/zheevd and prints max|V^H V - 1| and max|A V - V diag(W)|. EXPECTED RESULT Both numbers of order 1e-15 for every line, as with the new LAPACK interface. ACTUAL RESULT (legacy interface) zheev UPLO=U N=129 zero trailing rows=2 INFO=0 max|V^H V - 1| = 4.0e-15 max|A V - V W| = 4.4e-15 ok zheev UPLO=U N=130 zero trailing rows=2 INFO=0 max|V^H V - 1| = 9.8e-01 max|A V - V W| = 1.1e+00 <-- WRONG zheev UPLO=U N=130 zero trailing rows=1 INFO=0 max|V^H V - 1| = 4.7e-15 max|A V - V W| = 3.3e-15 ok zheev UPLO=U N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 1.1e+00 max|A V - V W| = 1.2e+00 <-- WRONG zheev UPLO=U N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 2.1e-01 max|A V - V W| = 2.2e+00 <-- WRONG zheev UPLO=U N=300 zero trailing rows=2 INFO=0 max|V^H V - 1| = 7.0e-01 max|A V - V W| = 1.5e+00 <-- WRONG zhegv UPLO=U N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 1.1e+00 max|A V - V W| = 1.2e+00 <-- WRONG the same matrices with UPLO = 'L' or zheevd: zheev UPLO=L N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 5.9e-15 max|A V - V W| = 3.6e-15 ok zhegv UPLO=L N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 4.4e-15 max|A V - V W| = 3.7e-15 ok zheevd UPLO=U N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 1.9e-15 max|A V - V W| = 1.4e-15 ok With -DACCELERATE_NEW_LAPACK every line is "ok" (1e-15). Code to reproduce the error: zheev_upper_bug.c.txt
2
0
150
5d
Inconsistent caseInsensitiveCompare behavior
(lldb) p [@"ΗΙzzz" caseInsensitiveCompare:@"ᾚabc"] (long long) -1 (lldb) p [@"ᾚabc" caseInsensitiveCompare:@"ΗΙzzz"] (long long) -1 Note the unicode char in the second string. The results can't be both -1, afaik, if one is -1 the other one should be +1. This causes inconsistent indexing in a sorted array resulting in obscure crashes of my app. Am I doing something wrong? Tested on iOS 27 and macOS 26.6.
6
0
189
5d
Watch faces not syncing to Apple Watch on iOS/watchOS 27 (FB25000073)
New faces I added in the iPhone Watch app showed up in My Faces but didn't reach my Apple Watch. Restarting both devices didn't help. The iPhone's logs showed the watch-face library was stuck in an automatic "reset sync" (not the Reset Sync Data button). With 65 watch apps installed, the reset was too big, hit the limit of 1000 messages per 5 minutes and failed, so new faces queued up behind it. One face took almost three hours to reach the watch. What worked for a while was removing the 7 watch apps with the most complications (I also pressed Reset Sync Data, so I'm not sure which did it). The reset dropped from 1946 to 927 messages and went through, and the stuck faces showed up the next time I added a face. About 90 minutes later a 939-message reset failed again, just over the limit counting the ~65 color-sync messages. To see if you're affected, stream your iPhone in Console.app on a Mac, add a face, and search for "requesting reset sync". I also filed FB25000090 because two queued Photos faces lost their photos when the reset went through. If you see it too, please file with sysdiagnoses from both devices (developer.apple.com/bug-reporting/profiles-and-logs) and mention FB25000073. iPhone 18 Pro on iOS 27.2 beta (24B5089g), Apple Watch Ultra 3 on watchOS 27.2 beta (24S5091f). Same on the public 27.0 release.
0
0
120
5d
NEURLFilterManager.localizedDescription is ignored by System Settings -> Network -> Filters
macOS 26.6, 26.7, 27.0 and 27.2 beta 1/2. Reproduced with Apple's SimpleURLFilter sample ("Filtering traffic by URL", WWDC25 session 234), built and run as a macOS app. The sample never sets localizedDescription, so I added one line to ConfigurationModel.save(configuration:) before saveToPreferences(): sharedFilterManager.localizedDescription = "Sentinel Filter Name" The property holds the value in memory: after loadFromPreferences(), the logged LocalizedStringResource still has key: "Sentinel Filter Name". But the effective configuration the system starts the session with has no localizedDescription — the session is named after the app: name = SimpleURLFilter applicationName = SimpleURLFilter application = com.example.apple-samplecode.SimpleURLFilterTC3Q7MAJXF (the rest of the nesessionmanager dump is the urlFilter dictionary, and it has no localizedDescription key). System Settings > Network > Filters shows the filter as URLFilter, not "Sentinel Filter Name". The stored configuration (/Library/Preferences/com.apple.networkextension.plist) has no localizedDescription key either, and injecting one by hand does not survive a nesessionmanager restart. Re-saving, removing and re-creating the configuration, and rebooting the Mac do not change the displayed name. Expected: the docs describe localizedDescription as "A string containing a description of the URL filter", and WWDC25 session 234's code sample ("Configure and manage URL Filter") sets it this way (manager.localizedDescription = "Alice's URL Filter"). For comparison, a NETransparentProxyManager configuration on the same Mac persists localizedDescription as the configuration's Name in the same plist, while the URL filter configuration has no such field. Filed as FB24987420.
1
0
128
5d
iOS leaves an accessory's no-internet Wi-Fi (NEHotspotConfiguration) for a saved network mid-session
We're building an iOS and Android app that transfers files to and from a device over a Wi-Fi network the device creates. That network has no internet access. The app gets the Wi-Fi credentials from the device (over Bluetooth, or from a QR code on its screen) and joins with NEHotspotConfiguration. Android works reliably. On iOS, partway through a session the phone leaves the device's network and joins a saved network that has internet, which breaks our connection to the device. Setup: iPhone 13 Pro, iOS 26.x NEHotspotConfiguration(ssid:passphrase:isWEP: false) with joinOnce = false. With joinOnce = true, iOS usually stays on the current internet Wi-Fi and never joins the device's network. WPA2. The device is at 192.168.4.1, and its DHCP server hands out the device as router and DNS. Device traffic: NWConnection (TCP) with prohibitedInterfaceTypes = [.cellular]. Server traffic: a separate NWConnection with requiredInterfaceType = .cellular. Wi-Fi Assist is off. Example: we read an 8 MB file from the device (30 s, no problem), then post it to our server over cellular (93 s). During the post, the device connection carries only a small message every ~15 s. 28 s into the post, NWPathMonitor shows Wi-Fi drop out for 3 s, and when it returns the phone is on the our primary network. Occasionally iOS shows a prompt asking whether to stay connected without internet, but usually it switches without asking. We haven't seen it switch during the file read, while the device connection is busy. Questions: Is there a supported way to keep iOS on a device's no-internet network for a whole session? Does traffic on the Wi-Fi interface (such as an active NWConnection) affect whether iOS switches away? Would a DHCP configuration without a router or DNS server change how iOS treats the network? Is joinOnce = false right for this, or can joinOnce = true join when the phone is already on an internet-capable Wi-Fi?
1
0
342
5d
watchOS 27 beta: EVERY app update kills WidgetKit complications until the watch is rebooted
Filed as FB24619522 — sysdiagnoses from both devices and the live logs are attached to the report. We ship WidgetKit complications, and on the watchOS 27 betas (24R5360a, paired with iOS 27 24A5430a) they die every time the app gets updated while they're on the active face. Within seconds they turn into empty placeholders and never come back on their own — opening the app, switching faces or reloading timelines from the app does nothing. The watch logs show the extension being killed during the install (normal), and after that watchOS simply can't launch the new copy any more: runningboardd: <OSLaunchdJob | handle=…>: start succeeded, info=spawn failed, error=111: Invalid or missing Program/ProgramArguments chronod(ChronoKit): Reload failed; 0 retries remaining: … "Unknown extension process" Only two things fix it, and both restart chronod: rebooting the watch, or switching the watch language and back (iPhone › Watch app › General › Language & Region, then give it a couple of minutes). Our second extension in the same bundle, which wasn't running during the install, came back fine — so this looks like an OS bug rather than something we can work around in code. iOS 27 widgets seem to have the same problem (this thread, and iPhone in Canada wrote it up on beta 4), and someone posted the identical log lines back in March. FB24619522 — the full story, both sysdiagnoses and the live logs are in the Feedback.
1
3
905
5d
Supported macOS design for safely terminating an app-owned helper subtree?
I am designing a bounded local diagnostic helper for macOS. It would run only purpose-built helpers supplied by the application, not third-party or untrusted code. The design question is how to stop exactly those helpers and their descendants on timeout, without affecting an unrelated process or incorrectly reporting that cleanup is complete. This is a public-API suitability question, not a report of a reproduced macOS bug. The intended diagnostic is not an antivirus or endpoint-detection product. The required properties are: Identify each owned process by its lifetime and association with this helper run, not a numeric PID or process-group ID alone. Account for descendants across fork/exec, parent exit or reparenting, and process-group/session changes. Observing that a descendant escaped is not equivalent to preventing an escape. Terminate only the still-owned processes without a stale-identity race between checking ownership and signaling. Report completion only when all owned descendants have stopped and no new owned descendants can appear. Leader exit, IPC disconnection, or an unauthenticated empty process list would not be sufficient. Lost events or uncertain membership must leave the outcome inconclusive. Which supported public API or service/containment architecture can provide these properties? If they cannot all be guaranteed, which constraint should be changed and what guarantee can the supported alternative actually provide? I have reviewed the documentation for es_new_descendants_client and es_sync_client. The remaining questions are: Is a descendant-scoped Endpoint Security client appropriate for this non-security-product diagnostic? If so, which documented entitlement and packaging route applies? I am asking about eligibility, not assuming it. Does any supported design combine lifetime-safe control with containment of the whole owned subtree, including concurrent descendant creation? Merely receiving events would not establish that property. What additional protocol, if any, makes a synchronization callback sufficient to establish complete termination when client destruction, event loss, and concurrent activity are possible? I am not treating that callback alone as proof that no owned process remains. I can redesign around a helper that cannot create descendants if that is the supported approach. In that case, what supported mechanism enforces that restriction and what termination guarantees remain? So far, a standalone C harness has passed eleven fabricated-input cases with assertions enabled. It exercised no Endpoint Security client, process-tree creation/enumeration/control, or application behavior. It is not a runtime reproducer for this API-design question and does not establish native lifecycle safety. Pointers to documented guarantees, limitations, or an Apple sample would help me choose the architecture before preparing a narrowly scoped native test. I am not seeking private APIs or a way to disable platform protections. No logs, source archive, or binary is attached.
1
0
409
5d
Sandbox Visa test card refused at provisioning (403) on supervised iPhones only; Mastercard fails at eligibility (500) everywhere
We test Apple Pay in the sandbox on supervised iPhones in a device lab (Apple Configurator supervision, no MDM enrollment, no SIM, iOS 26.x). Since late September two of the test cards from the Sandbox Testing page no longer add to Wallet. Discover test cards still add fine on the same devices and accounts. Filed as FB24994276 (Visa) and FB24994258 (Mastercard), with device logs and timestamps. Visa 4622 9431 2318 9285 (FB24994276), only on our lab devices: eligibility → 412 → TSM sync → 200, "received eligibility status: 1" terms shown and accepted provision → HTTP 403 → PKProvisioningErrorDomain Code=3 → "Invalid Card" Same result on two different lab iPhones, including one signed in to a brand-new sandbox account. The same new account and the same card add successfully on an unsupervised iPhone on a home network (iOS 18.2.1). Neither side sends location data. Mastercard 5204 2452 5046 0049 (FB24994258), on every device we tried, lab and home, iOS 18.2.1 and 26.x: eligibility → 412 → TSM sync → retry → HTTP 500 → PKProvisioningErrorDomain Code=5 Questions: What does the 403 at the provisioning step mean for the Visa card? Does supervision, the iOS version, our network egress, or the fact that our devices re-provision cards every test session play a role? Is the Mastercard sandbox environment currently broken, or is there a Mastercard test card that works? Happy to capture a sysdiagnose with the Wallet logging profile if that helps.
0
0
79
5d
iCloud Sync not working with iPhone, works fine for Mac.
I've been working on an app. It uses iCloud syncing. 48 hours ago everything was working 100%. Make a change on the iPhone it immediately changed on the Mac. Change on the Mac, it immediately changed on the iPhone. I didn't work on it yesterday. I updated to iOS26.4 on the iPhone and 26.4 on the Mac yesterday instead. Today, I pull up the project again. I made NO changes to the code or settings. Make a change on the iPhone it immediately updates on the Mac. Make a change on the Mac, nothing happens on the iPhone. I've waited an hour, and the change never happens. If you leave the iPhone app, then return, it updates as it should. It appears that iCloud's silent notification is to being received by the iPhone. Anyone else having the issue? Is there something new with iOS 26.4 that needs to be adjusted to get this to work? Again, works flawlessly with the Mac, just not with the iPhone.
39
17
11k
5d
Virtualization.framework VM execution ownership and crash reclamation on Intel macOS Monterey
Subject: Virtualization.framework VM execution ownership and crash reclamation on Intel macOS Monterey Hello, I’m investigating the lifecycle guarantees of Virtualization.framework on Intel macOS Monterey 12.7.x. The specific scenario is a VZVirtualMachine running a Linux guest. I need to understand the ownership and reclamation behavior when the process holding the VZVirtualMachine is abruptly terminated without calling stop() or performing normal cleanup. The key questions are: For a specific VZVirtualMachine on Intel macOS Monterey, which userspace task/process actually owns the Hypervisor VM and the vCPU threads backing guest execution? Is Hypervisor execution owned directly by the calling process, or by a separate process such as: com.apple.Virtualization.VirtualMachine or another Virtualization.framework backend? If the process holding the VZVirtualMachine is terminated with SIGKILL or crashes without executing cleanup code, is the underlying guest execution context necessarily destroyed? More specifically: Can guest vCPU execution continue after the client process has died? If a separate backend process owns the VM, is that backend guaranteed to terminate or destroy the VM when the client dies? Does this behavior apply to Intel macOS Monterey 12.7.x, or only to newer macOS releases? Is there a supported diagnostic on Monterey that can map one specific VZVirtualMachine instance to the task/process that actually owns its Hypervisor VM/vCPU execution? For example, would a diagnostic showing Hypervisor execution frames such as hv_vcpu_run in a process, combined with a reliable process-exit notification, be sufficient to establish that ownership relationship? If the Virtualization backend can survive the client process, what supported VM-specific recovery or termination mechanism is available to another process? The security property I need to establish is intentionally narrow: If the userspace owner of a VM is abruptly destroyed, guest computation must not be able to continue indefinitely as an independent execution domain. Persistent disk files or other inert VM artifacts are not the concern; the question is specifically about live guest/vCPU execution and its ownership lifecycle. I’m looking for the supported architectural contract or diagnostic approach, not undocumented implementation details. Target environment: macOS Monterey 12.7.x Intel x86_64 Virtualization.framework Hypervisor.framework Hardware virtualization available No private APIs or privileged/kernel extensions Thank you.
Replies
6
Boosts
0
Views
449
Activity
4d
Enrolment problems
Im trying to enrol on apple developer program for last couple of years and its always failing with first click and saying cannot be created at this time i. i tried to open many cases with apple and no feedback . any solution .
Replies
0
Boosts
0
Views
78
Activity
4d
How can a CarPlay voice-based conversational app let the car show and control an active conversation?
We make Alchemy, a leadership coaching app on the App Store. In Alchemy hands-free mode, a person talks with their coach out loud. It is a live, two-way voice conversation over the internet, started from a button in the app. Many of our users do this while out for a walk and especially while driving. Here is how it looks on Audroid Auto : We have requested the CarPlay voice-based conversation entitlement (com.apple.developer.carplay-voice-based-conversation) and plan to build the CarPlay screen with CPVoiceControlTemplate. Question: for an app with this entitlement, what is the supported way to let the car know that a conversation is active, so that the car can show it on its own displays (for example a name or title in the instrument cluster) and the driver can pause or end it with the steering wheel controls? What we want. On an Android phone connected to the same car (an Audi with a digital instrument cluster), our voice conversation appears in the cluster's header as an active call with a name, and the steering wheel button ends it. We would like the same for iPhone users, using the APIs Apple intends. What we tried. iPhone 13, iOS 27.2 beta, wired CarPlay, same car: We started the conversation as an outgoing CallKit call (CXStartCallAction, generic handle, localizedCallerName set), with the audio background modes. The phone showed a call. The instrument cluster did not change, and the CarPlay Phone screen showed nothing. With the audio background mode only, the conversation works well through the car speakers and microphone, on the Home Screen and with the phone locked. The instrument cluster stays on the radio station, and CarPlay shows only the orange microphone indicator. If the car's own displays cannot show a voice-based conversational app's session, that is a useful answer too. In that case, what can the Voice Control template show the driver, and can the steering wheel controls act on the conversation at all? The goal is truly hands free so nobody gets a ticket while getting coaching help. 👍 Thank you.
Replies
0
Boosts
0
Views
64
Activity
4d
Kernel panic "m->m_flags & M_PKTHDR" in uipc_mbuf.c on SMB clients over 10 GbE (macOS 26)
We have a group of Macs that mount SMB shares over 10 GbE with jumbo frames (MTU 9000). Since late June, they have been kernel panicking several times a day with the same assertion: panic(cpu N caller ...): assertion failed: m->m_flags & M_PKTHDR, file: .../xnu/bsd/kern/uipc_mbuf.c, line: 4839 @uipc_socket.c:8260 Panicked thread: dlil_input_en0 Last started kext: com.apple.filesystems.smbfs 6.0.1 Environment Clients: Mac Studio (M1 Max and M1 Ultra) and Mac Pro (2019, Intel with T2), using the built-in 10GBASE-T at MTU 9000 macOS 26.5.1 (25F80), 26.6.2 (25G83) and 26.7 (25G229); it panics on all three Servers: Samba-based NAS, SMB 3.1.1, signing on, encryption off Filed as FB24912731 What we've found It still panics with our third-party EDR fully uninstalled. The Mac that panics needs an active SMB session. A Mac left on the network without a share mounted stayed up through several events that took down the others. Panics are often simultaneous across machines: two to six Macs, with different hardware and different macOS builds, within the same minute. It doesn't need sustained heavy throughput. Some panics came within minutes of reconnecting, during light editing. Setting kern.skywalk.flowswitch.rx_agg_tcp_host=0 did not help. The switch and server links stay up, and spanning tree doesn't change during these events. Only the Macs' ports drop. In one server-side capture, the client stopped sending within about 0.2 ms of receiving a READ response made of 8948-byte frames. That fits the panicked thread being dlil_input. Two existing threads look related Kernel panic using Vagrant synced folders via NFS beginning with macOS 15.4 (FB17853906). A DTS reply there said the issue is in kernel mbuf management and that SMB "is very likely to experience a similar panic." Incorrect packet handling in SMBClient MacOS 26, which describes a race in SMBClient under heavy load above about 10 Gbps. Questions Is this the same underlying issue as FB17853906, and is a fix planned for macOS 26? Our 2019 Mac Pros can't move to a later major release. Is there a known workaround, such as a sysctl, an nsmb.conf option, or a change to MTU or offload settings? Is there logging or a diagnostic we can leave enabled to capture more state at panic time? We can't reproduce this on demand, but between several machines we see it multiple times a day. We can provide full panic reports, sysdiagnoses, and packet captures from both client and server sides.
Replies
6
Boosts
0
Views
465
Activity
4d
Symbolicating kernel backtraces on Apple Silicon
I am able to symbolicate kernel backtraces for addresses that belong to my kext. Is it possible to symbolicate kernel backtraces for addresses that lie beyond my kext and reference kernel code? Sample kernel panic log
Replies
35
Boosts
0
Views
2.6k
Activity
4d
Access to Matter “characteristic” in a HomeKit app?
Hi there, I am working on a (Mac Catalyst) HomeKit my own private application, which observes different characteristics of different accessories. This works (also thanks to the advice here, thanks again to all who helped!) like a charm. Now I've found that one of my outlets which is connected through Matter supports power consumption (in Home.app), but there is no characteristic for that, all I can see is its power state. Self-evidently, access to the consumption would be something Matter-specific. At this moment, to save time, I'd rather not study the complete Matter kit in detail if it can be dodged for this particular very limited goal. Is it possible just as simply as possible to read in (if readable) and observe (if observable) those extra Matter characteristics (if any) for an HMAccessory, presumably through its matterNodeID somehow? I'd be grateful for a sample code, if some is available (preferably ObjC, but of course Swift better'n nothing). Thanks a lot!
Replies
5
Boosts
0
Views
129
Activity
4d
VZDiskImageStorageDeviceAttachment lifecycle after guest shutdown
After a normal macOS guest shutdown, what is the documented lifecycle for VZDiskImageStorageDeviceAttachment? What cleanup is required before the host can safely read the backing disk image, and is there a supported completion notification for outstanding I/O?
Replies
0
Boosts
1
Views
76
Activity
4d
Family Controls / DeviceActivity: Can an on-device usage result be shared as an abstract score or goal-completion event?
I’m evaluating an iOS app that uses Family Controls / DeviceActivity for an adult user’s voluntary personal device-management and digital-wellbeing goals. The app would also have an optional social competition feature where friends participate in fantasy-style leagues based on completion of their individual digital-wellbeing goals. I’m trying to understand the restrictions in Apple Developer Program License Agreement Section 3.3.3(P), specifically whether a privacy-preserving result derived locally from Family Controls / DeviceActivity can leave the device when the underlying usage data never does. I’m considering three architectures: A — Locally derived fantasy score DeviceActivity information is evaluated entirely on-device and converted locally into an abstract score. The server receives only: fantasy_points = 82 No Screen Time duration, app identity, website activity, bundle identifier, or underlying usage information leaves the device. B — Binary goal completion A user creates a private usage goal, such as remaining below their chosen daily device-usage threshold. The goal is evaluated entirely on-device. The server receives only: goal_completed = true The server then awards predetermined fantasy points. It never receives the underlying Screen Time value. C — Opaque challenge completion A user privately selects an app/activity goal. DeviceActivity evaluates the threshold locally. The server receives only: challenge_id = C928 completed = true The server knows C928 is worth a predetermined number of points, but does not receive the selected app identity, usage duration, Screen Time quantity, or other underlying DeviceActivity information. In all three approaches, raw Screen Time duration, per-app usage duration, application/bundle identity, website activity, DeviceActivity reports, and underlying historical usage records would remain on-device. Friends would only see fantasy points, matchup results, standings, and/or achievements. My question: Under Section 3.3.3(P) and the Family Controls requirements, are any of A, B, or C permitted? More specifically, does Apple consider an abstract score, boolean goal-completion result, or opaque challenge-completion result to itself be “device or usage data” when it was derived from Family Controls / DeviceActivity? If none of these architectures are permitted, is there a supported privacy-preserving architecture that allows an on-device DeviceActivity evaluation to affect a server-side social or multiplayer feature without transmitting the underlying device/usage information? I’m trying to establish the compliant architecture before development rather than build around an incorrect interpretation of the Family Controls requirements.
Replies
0
Boosts
0
Views
269
Activity
4d
Supported way to test Family Controls .child authorization without using a child's personal account?
I'm developing an iOS parent-child app that uses FamilyControls and DeviceActivity. Before distribution, I need to test AuthorizationCenter.shared.requestAuthorization(for: .child), including the guardian approval flow. So far I have tested .individual, which authenticates the device owner and does not exercise the child flow. Apple Developer Program Support directed me to this forum. What is the Apple-supported way to test this flow in this situation? Is there an Apple-supported test-only account or setup for this flow without using a child's personal Apple Account? If so, where are its requirements documented? If not, what is the recommended alternative? Can Sandbox Apple Accounts used for StoreKit Family Sharing tests be used to sign in to iCloud and test FamilyControls .child, or are they limited to purchase testing? Is there a supported simulator or other test method for guardian approval, or must this be verified using a child Apple Account in a real Family Sharing group on physical devices? I want to follow Apple's account rules and test the actual parental authorization path before distribution. References to official guidance would be appreciated.
Replies
0
Boosts
0
Views
65
Activity
4d
Apple Pay merchant domain verification fails despite valid TLS configuration
We are unable to verify our Apple Pay merchant domains. Apple Developer Portal returns: “Domain verification failed. Review your TLS Certificate configuration to confirm that the certificate is accessible and a supported TLS Cipher Suite is used.” We have confirmed that the verification endpoints are publicly accessible, return HTTP 200, and support TLS 1.2/1.3 with valid certificates and supported cipher suites. The domains are behind Cloudflare. However, when verification is triggered, we do not see an HTTP request from Apple in our Cloudflare request logs. Has anyone experienced a similar issue with Apple Pay merchant domain verification, especially with domains behind Cloudflare? We have also submitted a report through Feedback Assistant.
Replies
0
Boosts
0
Views
81
Activity
4d
CloudKit container data disappeared.
Most of my CloudKit data has been missing from my container for over a week. No response from Apple support. I am very worried it may be unrecoverable.my apps can not access the data and the dashboard shows a huge amount of files and data in other files missing. These are needed to operate our chiropractic clinic and contain patient and transaction history. This might be a disaster for us.
Replies
4
Boosts
0
Views
588
Activity
4d
Bug in Accelerate Lapack - Wrong eigenvectors
In the LAPACK interface of Accelerate (the default, without ACCELERATE_NEW_LAPACK), zheev with JOBZ='V', UPLO='U' returns eigenvectors that are neither orthonormal nor eigenvectors, while INFO=0. The eigenvalues are correct. zhegv with UPLO='U' fails the same way (tested with B = identity). It happens when: the matrix is complex Hermitian of order N >= 130 (N = 129 is correct, N = 130 already fails, N = 300 fails), and its last two or more rows and columns are exactly zero (one zero row is fine). Zero rows at the start or in the middle are fine. Banded and dense matrices both fail. On the same matrices the following are correct to rounding (1e-15): zheev and zhegv with UPLO='L', zheevd with UPLO='U', dsyev with UPLO='U' on real symmetric matrices of the same shape, zheev with UPLO='U' through the new LAPACK interface (-DACCELERATE_NEW_LAPACK). Since only the eigenvectors are wrong, and only above N=129 (presumably where zhetrd switches to its blocked code), the fault seems to be in the blocked Householder reduction or in the back-transformation (zhetrd/zlatrd or zungtr/zungql) of the legacy library, for columns that are zero. Asking LAPACK for the optimal LWORK (LWORK = -1 query) does not change the result. We found this in a physics code (Quanty, quanty.org), where a matrix of this shape arises naturally: a block tridiagonal (block Lanczos) matrix whose last block is padded with zeros after deflation. The wrong eigenvectors silently degraded results by 1e-4 relative, instead of 1e-15. STEPS TO REPRODUCE Save the attached zheev_upper_bug.c. clang -O2 zheev_upper_bug.c -o zheev_upper_bug -framework Accelerate ./zheev_upper_bug For comparison: clang -O2 -DACCELERATE_NEW_LAPACK zheev_upper_bug.c -o zheev_upper_bug_new -framework Accelerate && ./zheev_upper_bug_new The program builds a random Hermitian matrix (fixed seed, entries in [-0.5,0.5), bandwidth 11 or dense), zeroes its last NZERO rows and columns, calls zheev/zhegv/zheevd and prints max|V^H V - 1| and max|A V - V diag(W)|. EXPECTED RESULT Both numbers of order 1e-15 for every line, as with the new LAPACK interface. ACTUAL RESULT (legacy interface) zheev UPLO=U N=129 zero trailing rows=2 INFO=0 max|V^H V - 1| = 4.0e-15 max|A V - V W| = 4.4e-15 ok zheev UPLO=U N=130 zero trailing rows=2 INFO=0 max|V^H V - 1| = 9.8e-01 max|A V - V W| = 1.1e+00 <-- WRONG zheev UPLO=U N=130 zero trailing rows=1 INFO=0 max|V^H V - 1| = 4.7e-15 max|A V - V W| = 3.3e-15 ok zheev UPLO=U N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 1.1e+00 max|A V - V W| = 1.2e+00 <-- WRONG zheev UPLO=U N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 2.1e-01 max|A V - V W| = 2.2e+00 <-- WRONG zheev UPLO=U N=300 zero trailing rows=2 INFO=0 max|V^H V - 1| = 7.0e-01 max|A V - V W| = 1.5e+00 <-- WRONG zhegv UPLO=U N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 1.1e+00 max|A V - V W| = 1.2e+00 <-- WRONG the same matrices with UPLO = 'L' or zheevd: zheev UPLO=L N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 5.9e-15 max|A V - V W| = 3.6e-15 ok zhegv UPLO=L N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 4.4e-15 max|A V - V W| = 3.7e-15 ok zheevd UPLO=U N=138 zero trailing rows=5 INFO=0 max|V^H V - 1| = 1.9e-15 max|A V - V W| = 1.4e-15 ok With -DACCELERATE_NEW_LAPACK every line is "ok" (1e-15). Code to reproduce the error: zheev_upper_bug.c.txt
Replies
2
Boosts
0
Views
150
Activity
5d
Inconsistent caseInsensitiveCompare behavior
(lldb) p [@"ΗΙzzz" caseInsensitiveCompare:@"ᾚabc"] (long long) -1 (lldb) p [@"ᾚabc" caseInsensitiveCompare:@"ΗΙzzz"] (long long) -1 Note the unicode char in the second string. The results can't be both -1, afaik, if one is -1 the other one should be +1. This causes inconsistent indexing in a sorted array resulting in obscure crashes of my app. Am I doing something wrong? Tested on iOS 27 and macOS 26.6.
Replies
6
Boosts
0
Views
189
Activity
5d
Watch faces not syncing to Apple Watch on iOS/watchOS 27 (FB25000073)
New faces I added in the iPhone Watch app showed up in My Faces but didn't reach my Apple Watch. Restarting both devices didn't help. The iPhone's logs showed the watch-face library was stuck in an automatic "reset sync" (not the Reset Sync Data button). With 65 watch apps installed, the reset was too big, hit the limit of 1000 messages per 5 minutes and failed, so new faces queued up behind it. One face took almost three hours to reach the watch. What worked for a while was removing the 7 watch apps with the most complications (I also pressed Reset Sync Data, so I'm not sure which did it). The reset dropped from 1946 to 927 messages and went through, and the stuck faces showed up the next time I added a face. About 90 minutes later a 939-message reset failed again, just over the limit counting the ~65 color-sync messages. To see if you're affected, stream your iPhone in Console.app on a Mac, add a face, and search for "requesting reset sync". I also filed FB25000090 because two queued Photos faces lost their photos when the reset went through. If you see it too, please file with sysdiagnoses from both devices (developer.apple.com/bug-reporting/profiles-and-logs) and mention FB25000073. iPhone 18 Pro on iOS 27.2 beta (24B5089g), Apple Watch Ultra 3 on watchOS 27.2 beta (24S5091f). Same on the public 27.0 release.
Replies
0
Boosts
0
Views
120
Activity
5d
NEURLFilterManager.localizedDescription is ignored by System Settings -> Network -> Filters
macOS 26.6, 26.7, 27.0 and 27.2 beta 1/2. Reproduced with Apple's SimpleURLFilter sample ("Filtering traffic by URL", WWDC25 session 234), built and run as a macOS app. The sample never sets localizedDescription, so I added one line to ConfigurationModel.save(configuration:) before saveToPreferences(): sharedFilterManager.localizedDescription = "Sentinel Filter Name" The property holds the value in memory: after loadFromPreferences(), the logged LocalizedStringResource still has key: "Sentinel Filter Name". But the effective configuration the system starts the session with has no localizedDescription — the session is named after the app: name = SimpleURLFilter applicationName = SimpleURLFilter application = com.example.apple-samplecode.SimpleURLFilterTC3Q7MAJXF (the rest of the nesessionmanager dump is the urlFilter dictionary, and it has no localizedDescription key). System Settings > Network > Filters shows the filter as URLFilter, not "Sentinel Filter Name". The stored configuration (/Library/Preferences/com.apple.networkextension.plist) has no localizedDescription key either, and injecting one by hand does not survive a nesessionmanager restart. Re-saving, removing and re-creating the configuration, and rebooting the Mac do not change the displayed name. Expected: the docs describe localizedDescription as "A string containing a description of the URL filter", and WWDC25 session 234's code sample ("Configure and manage URL Filter") sets it this way (manager.localizedDescription = "Alice's URL Filter"). For comparison, a NETransparentProxyManager configuration on the same Mac persists localizedDescription as the configuration's Name in the same plist, while the URL filter configuration has no such field. Filed as FB24987420.
Replies
1
Boosts
0
Views
128
Activity
5d
iOS leaves an accessory's no-internet Wi-Fi (NEHotspotConfiguration) for a saved network mid-session
We're building an iOS and Android app that transfers files to and from a device over a Wi-Fi network the device creates. That network has no internet access. The app gets the Wi-Fi credentials from the device (over Bluetooth, or from a QR code on its screen) and joins with NEHotspotConfiguration. Android works reliably. On iOS, partway through a session the phone leaves the device's network and joins a saved network that has internet, which breaks our connection to the device. Setup: iPhone 13 Pro, iOS 26.x NEHotspotConfiguration(ssid:passphrase:isWEP: false) with joinOnce = false. With joinOnce = true, iOS usually stays on the current internet Wi-Fi and never joins the device's network. WPA2. The device is at 192.168.4.1, and its DHCP server hands out the device as router and DNS. Device traffic: NWConnection (TCP) with prohibitedInterfaceTypes = [.cellular]. Server traffic: a separate NWConnection with requiredInterfaceType = .cellular. Wi-Fi Assist is off. Example: we read an 8 MB file from the device (30 s, no problem), then post it to our server over cellular (93 s). During the post, the device connection carries only a small message every ~15 s. 28 s into the post, NWPathMonitor shows Wi-Fi drop out for 3 s, and when it returns the phone is on the our primary network. Occasionally iOS shows a prompt asking whether to stay connected without internet, but usually it switches without asking. We haven't seen it switch during the file read, while the device connection is busy. Questions: Is there a supported way to keep iOS on a device's no-internet network for a whole session? Does traffic on the Wi-Fi interface (such as an active NWConnection) affect whether iOS switches away? Would a DHCP configuration without a router or DNS server change how iOS treats the network? Is joinOnce = false right for this, or can joinOnce = true join when the phone is already on an internet-capable Wi-Fi?
Replies
1
Boosts
0
Views
342
Activity
5d
watchOS 27 beta: EVERY app update kills WidgetKit complications until the watch is rebooted
Filed as FB24619522 — sysdiagnoses from both devices and the live logs are attached to the report. We ship WidgetKit complications, and on the watchOS 27 betas (24R5360a, paired with iOS 27 24A5430a) they die every time the app gets updated while they're on the active face. Within seconds they turn into empty placeholders and never come back on their own — opening the app, switching faces or reloading timelines from the app does nothing. The watch logs show the extension being killed during the install (normal), and after that watchOS simply can't launch the new copy any more: runningboardd: <OSLaunchdJob | handle=…>: start succeeded, info=spawn failed, error=111: Invalid or missing Program/ProgramArguments chronod(ChronoKit): Reload failed; 0 retries remaining: … "Unknown extension process" Only two things fix it, and both restart chronod: rebooting the watch, or switching the watch language and back (iPhone › Watch app › General › Language & Region, then give it a couple of minutes). Our second extension in the same bundle, which wasn't running during the install, came back fine — so this looks like an OS bug rather than something we can work around in code. iOS 27 widgets seem to have the same problem (this thread, and iPhone in Canada wrote it up on beta 4), and someone posted the identical log lines back in March. FB24619522 — the full story, both sysdiagnoses and the live logs are in the Feedback.
Replies
1
Boosts
3
Views
905
Activity
5d
Supported macOS design for safely terminating an app-owned helper subtree?
I am designing a bounded local diagnostic helper for macOS. It would run only purpose-built helpers supplied by the application, not third-party or untrusted code. The design question is how to stop exactly those helpers and their descendants on timeout, without affecting an unrelated process or incorrectly reporting that cleanup is complete. This is a public-API suitability question, not a report of a reproduced macOS bug. The intended diagnostic is not an antivirus or endpoint-detection product. The required properties are: Identify each owned process by its lifetime and association with this helper run, not a numeric PID or process-group ID alone. Account for descendants across fork/exec, parent exit or reparenting, and process-group/session changes. Observing that a descendant escaped is not equivalent to preventing an escape. Terminate only the still-owned processes without a stale-identity race between checking ownership and signaling. Report completion only when all owned descendants have stopped and no new owned descendants can appear. Leader exit, IPC disconnection, or an unauthenticated empty process list would not be sufficient. Lost events or uncertain membership must leave the outcome inconclusive. Which supported public API or service/containment architecture can provide these properties? If they cannot all be guaranteed, which constraint should be changed and what guarantee can the supported alternative actually provide? I have reviewed the documentation for es_new_descendants_client and es_sync_client. The remaining questions are: Is a descendant-scoped Endpoint Security client appropriate for this non-security-product diagnostic? If so, which documented entitlement and packaging route applies? I am asking about eligibility, not assuming it. Does any supported design combine lifetime-safe control with containment of the whole owned subtree, including concurrent descendant creation? Merely receiving events would not establish that property. What additional protocol, if any, makes a synchronization callback sufficient to establish complete termination when client destruction, event loss, and concurrent activity are possible? I am not treating that callback alone as proof that no owned process remains. I can redesign around a helper that cannot create descendants if that is the supported approach. In that case, what supported mechanism enforces that restriction and what termination guarantees remain? So far, a standalone C harness has passed eleven fabricated-input cases with assertions enabled. It exercised no Endpoint Security client, process-tree creation/enumeration/control, or application behavior. It is not a runtime reproducer for this API-design question and does not establish native lifecycle safety. Pointers to documented guarantees, limitations, or an Apple sample would help me choose the architecture before preparing a narrowly scoped native test. I am not seeking private APIs or a way to disable platform protections. No logs, source archive, or binary is attached.
Replies
1
Boosts
0
Views
409
Activity
5d
Sandbox Visa test card refused at provisioning (403) on supervised iPhones only; Mastercard fails at eligibility (500) everywhere
We test Apple Pay in the sandbox on supervised iPhones in a device lab (Apple Configurator supervision, no MDM enrollment, no SIM, iOS 26.x). Since late September two of the test cards from the Sandbox Testing page no longer add to Wallet. Discover test cards still add fine on the same devices and accounts. Filed as FB24994276 (Visa) and FB24994258 (Mastercard), with device logs and timestamps. Visa 4622 9431 2318 9285 (FB24994276), only on our lab devices: eligibility → 412 → TSM sync → 200, "received eligibility status: 1" terms shown and accepted provision → HTTP 403 → PKProvisioningErrorDomain Code=3 → "Invalid Card" Same result on two different lab iPhones, including one signed in to a brand-new sandbox account. The same new account and the same card add successfully on an unsupervised iPhone on a home network (iOS 18.2.1). Neither side sends location data. Mastercard 5204 2452 5046 0049 (FB24994258), on every device we tried, lab and home, iOS 18.2.1 and 26.x: eligibility → 412 → TSM sync → retry → HTTP 500 → PKProvisioningErrorDomain Code=5 Questions: What does the 403 at the provisioning step mean for the Visa card? Does supervision, the iOS version, our network egress, or the fact that our devices re-provision cards every test session play a role? Is the Mastercard sandbox environment currently broken, or is there a Mastercard test card that works? Happy to capture a sysdiagnose with the Wallet logging profile if that helps.
Replies
0
Boosts
0
Views
79
Activity
5d
iCloud Sync not working with iPhone, works fine for Mac.
I've been working on an app. It uses iCloud syncing. 48 hours ago everything was working 100%. Make a change on the iPhone it immediately changed on the Mac. Change on the Mac, it immediately changed on the iPhone. I didn't work on it yesterday. I updated to iOS26.4 on the iPhone and 26.4 on the Mac yesterday instead. Today, I pull up the project again. I made NO changes to the code or settings. Make a change on the iPhone it immediately updates on the Mac. Make a change on the Mac, nothing happens on the iPhone. I've waited an hour, and the change never happens. If you leave the iPhone app, then return, it updates as it should. It appears that iCloud's silent notification is to being received by the iPhone. Anyone else having the issue? Is there something new with iOS 26.4 that needs to be adjusted to get this to work? Again, works flawlessly with the Mac, just not with the iPhone.
Replies
39
Boosts
17
Views
11k
Activity
5d