Overview

Post

Replies

Boosts

Views

Activity

iOS leaves an accessory's no-internet Wi-Fi (NEHotspotConfiguration) for a saved network mid-session
We're building an iOS and Android app that transfers files to and from a device over a Wi-Fi network the device creates. That network has no internet access. The app gets the Wi-Fi credentials from the device (over Bluetooth, or from a QR code on its screen) and joins with NEHotspotConfiguration. Android works reliably. On iOS, partway through a session the phone leaves the device's network and joins a saved network that has internet, which breaks our connection to the device. Setup: iPhone 13 Pro, iOS 26.x NEHotspotConfiguration(ssid:passphrase:isWEP: false) with joinOnce = false. With joinOnce = true, iOS usually stays on the current internet Wi-Fi and never joins the device's network. WPA2. The device is at 192.168.4.1, and its DHCP server hands out the device as router and DNS. Device traffic: NWConnection (TCP) with prohibitedInterfaceTypes = [.cellular]. Server traffic: a separate NWConnection with requiredInterfaceType = .cellular. Wi-Fi Assist is off. Example: we read an 8 MB file from the device (30 s, no problem), then post it to our server over cellular (93 s). During the post, the device connection carries only a small message every ~15 s. 28 s into the post, NWPathMonitor shows Wi-Fi drop out for 3 s, and when it returns the phone is on the our primary network. Occasionally iOS shows a prompt asking whether to stay connected without internet, but usually it switches without asking. We haven't seen it switch during the file read, while the device connection is busy. Questions: Is there a supported way to keep iOS on a device's no-internet network for a whole session? Does traffic on the Wi-Fi interface (such as an active NWConnection) affect whether iOS switches away? Would a DHCP configuration without a router or DNS server change how iOS treats the network? Is joinOnce = false right for this, or can joinOnce = true join when the phone is already on an internet-capable Wi-Fi?
0
0
6
17m
How to use ClothGrabComponent?
I've simulated a piece of cloth using https://developer.apple.com/documentation/realitykit/physics-cloth-simulation I would like to grab the cloth like what I can in Marvellous Designer. I found the ClothGrabComponent at https://developer.apple.com/documentation/realitykit/clothgrabcomponent However, after I added the ClothGrabComponent to the cloth entity, I am still not able to grab it. Is there any sample code to show me how to grab the cloth? Thank you.
2
0
693
30m
Supported macOS design for safely terminating an app-owned helper subtree?
I am designing a bounded local diagnostic helper for macOS. It would run only purpose-built helpers supplied by the application, not third-party or untrusted code. The design question is how to stop exactly those helpers and their descendants on timeout, without affecting an unrelated process or incorrectly reporting that cleanup is complete. This is a public-API suitability question, not a report of a reproduced macOS bug. The intended diagnostic is not an antivirus or endpoint-detection product. The required properties are: Identify each owned process by its lifetime and association with this helper run, not a numeric PID or process-group ID alone. Account for descendants across fork/exec, parent exit or reparenting, and process-group/session changes. Observing that a descendant escaped is not equivalent to preventing an escape. Terminate only the still-owned processes without a stale-identity race between checking ownership and signaling. Report completion only when all owned descendants have stopped and no new owned descendants can appear. Leader exit, IPC disconnection, or an unauthenticated empty process list would not be sufficient. Lost events or uncertain membership must leave the outcome inconclusive. Which supported public API or service/containment architecture can provide these properties? If they cannot all be guaranteed, which constraint should be changed and what guarantee can the supported alternative actually provide? I have reviewed the documentation for es_new_descendants_client and es_sync_client. The remaining questions are: Is a descendant-scoped Endpoint Security client appropriate for this non-security-product diagnostic? If so, which documented entitlement and packaging route applies? I am asking about eligibility, not assuming it. Does any supported design combine lifetime-safe control with containment of the whole owned subtree, including concurrent descendant creation? Merely receiving events would not establish that property. What additional protocol, if any, makes a synchronization callback sufficient to establish complete termination when client destruction, event loss, and concurrent activity are possible? I am not treating that callback alone as proof that no owned process remains. I can redesign around a helper that cannot create descendants if that is the supported approach. In that case, what supported mechanism enforces that restriction and what termination guarantees remain? So far, a standalone C harness has passed eleven fabricated-input cases with assertions enabled. It exercised no Endpoint Security client, process-tree creation/enumeration/control, or application behavior. It is not a runtime reproducer for this API-design question and does not establish native lifecycle safety. Pointers to documented guarantees, limitations, or an Apple sample would help me choose the architecture before preparing a narrowly scoped native test. I am not seeking private APIs or a way to disable platform protections. No logs, source archive, or binary is attached.
1
0
76
1h
navigationTransition in NavigationStack does not work in sheets in iOS 27
navigationTransition(_ style: some NavigationTransition) in NavigationStack does not work in sheets in iOS 27 and iPadOS 27. NavigationTransitions allow a smooth transition from one view to another. An app perfectly working on iOS/iPadOS 26.x does not work correctly on iOS/iPadOS 27.x We have made a simple sample project to show the issue. On 26 OSes there are smooth transitions, on 27.0 when a navigationTransition should occur after a push in the NavigationStack in a sheet, the sheet becomes invisible (the main screen reappears) and suddenly the new view appears without transition. Sample project in Feedback FB24996035 Sample line with the issue SecondPathView(namespace: namespace, path: $path) .navigationTransition(.zoom(sourceID: transitionFromFirstPathId, in: namespace))
0
0
12
1h
iOS 27: Scroll edge effect region sizes on UIRefreshControl presence, not its height
Summary On iOS 27 the top scroll edge effect of a UITableView is sized around the UIRefreshControl as an edge element, but appears to key on the control's presence in the scroll view rather than its current height. After endRefreshing(), the control collapses to zero height but stays attached, and the effect region keeps reserving a refresh-control's worth of space. The first row stays blurred and dimmed even though it is scrolled fully clear of the navigation bar. Environment iOS 27 (beta), iPhone Xcode 27.0.0 Beta 4 UIKit, UITableView inside a UINavigationController Reproduces with the default edge effect style and with an explicit .soft Steps to reproduce Push a UITableViewController with a UIRefreshControl onto a navigation stack. Ensure content extends under the navigation bar (default for UITableViewController). Pull to refresh and let the refresh end. Observe the first row after the refresh control has retracted. Expected Once the control retracts, the edge effect returns to its pre-pull height and the first row renders crisply. Actual The region stays roughly one refresh-control height too tall and the first row stays blurred. Row positions are unaffected — content offset and adjustedContentInset are correct. Only the extent of the effect is wrong. It corrects itself on the next push/pop. Two probes that isolate it These narrow the cause to the control's presence rather than a general staleness: Re-assigning tableView.topEdgeEffect.style after endRefreshing(), including on a later runloop turn, does NOT correct the region. The style is not what is stale. Detaching the control DOES correct it immediately: tableView.refreshControl = nil So the region is measured from the control being in the hierarchy, and is never re-measured when the control merely collapses. Secondary issue A UIRefreshControl that has been detached is inert if the same instance is re-assigned: tableView.refreshControl = nil tableView.refreshControl = sameInstance // never triggers again A freshly constructed UIRefreshControl must be assigned instead. This is not documented and looks like a second bug. Minimal sample Attached. A UITableViewController with a refresh control and a "Push" bar button that pushes and pops an empty view controller, so the incorrect region and the post-navigation correction can be compared in one run. Related FB20756572 reports the same "edge-effect extent is stale until the next navigation" behaviour for UIScrollEdgeElementContainerInteraction sizing, and notes a change in iOS 27 seed 1. That report received no reply.
2
0
1k
1h
Cannot run Catalyst app on other devices?!?
I prepare a private project in Xcode, use Archive, Distribute/Copy, save the application somewhere. Copy it to my other computer, run. Works perfectly with normal MacOS applications. With Catalyst ones though it does not; whatever I try, all I get is “The application XXX cannot be opened”. What do I do wrong and how to fix the problem? Thanks!
0
0
17
1h
Individual account converted to Organization — sole proprietor needs to return to Individual
Hi everyone, I’m looking for advice regarding an Apple Developer Program membership issue. I originally had an Individual membership, which I recently converted to an Organization membership for my business. However, my business is a French micro-entreprise / entreprise individuelle (sole proprietorship). I subsequently discovered that Apple’s documentation states that an individual or sole proprietor/single-person business should enroll as an Individual. The Organization membership is also causing problems with the tax forms because my business is not a separate legal entity from myself. Apple Developer Support confirmed that Organization → Individual conversion is not supported. My app is currently only in TestFlight. It has never been released on the App Store and has no IAP or subscriptions submitted for review. I’m therefore considering creating a new Apple Account and enrolling again in the Apple Developer Program as an Individual, then recreating the app under that account. Has anyone been in this situation? In particular: Can the same person enroll in a new Individual Developer Program membership using a different Apple Account while still being the Account Holder of an existing Organization membership? Are there any identity-verification issues when doing this? Is creating a new Individual membership the recommended solution when an Organization membership cannot be converted back? I already have an open case with Apple Developer Support but haven’t received clarification yet. Thanks for any advice or experience with a similar situation.
0
0
11
1h
Supported completeness and lifecycle guarantees for es_new_descendants_client
Hello Apple Developer Technical Support, I am evaluating es_new_descendants_client for a local command runner that must report success only after its workload and every process descended from that workload have exited. If observation is incomplete or ambiguous, the runner must report failure. This is a design inquiry, not a report of a reproduced operating-system defect; no entitled prototype has been tested. The proposed observer would create its client and subscribe to lifecycle notifications before launching any workload. It would maintain a registry using process-lifetime identities, add processes on creation and remove them on exit. An unmatched event, missing required field, detected loss or observer failure would invalidate the run. It would consider closure only after all registered workload processes had exited. We have not established that these rules are sufficient. Could you clarify which of the following properties are supported API guarantees, and identify any that applications must not rely on? A documented reference or an explicit statement that a guarantee is unavailable would both help. Please identify applicable macOS/SDK versions and any known version-dependent limitations. 1. Membership and creation-event coverage Does the observed subtree retain a process and all of its future descendants after its original parent exits, it is reparented, it double-forks, or it changes process group/session with setpgid or setsid? Could a process remain observable for exit while creation events for its children become invisible? For a workload launched after successful subscription, does every successful process-creation path—including fork, vfork and posix_spawn—produce a lifecycle event sufficient to register the new process before closure can be declared? Which event and identity fields should be used for each path, including a child that exits without a successful exec? Does the calling observer receive the necessary event for its own initial workload launch? 2. Ordering and the meaning of exit Is there a supported per-client ordering guarantee that every child-creation event from a process is delivered before that process's exit notification, including concurrent creation and exit? Can the child's events arrive before the event that introduces that child? Please distinguish kernel enqueue order, handler delivery order and any processing order the application must impose. At what lifecycle boundary is ES_EVENT_TYPE_NOTIFY_EXIT generated? Does it establish that the identified process can no longer execute or initiate writes, or can relevant activity continue after the notification? We would not equate process exit with filesystem durability or completion of work already delegated to other processes. 3. Muting and other visibility filters Does a newly created descendants client have default process, path or target-path mutes that can suppress fork/exit notifications? What supported sequence of configuration and inspection calls establishes complete lifecycle visibility before launch, including mute inversion and executable-path changes? Apart from subscription and muting, are there policy, security, rate-limit or client-type exclusions that can suppress those events? Which suppressed events, if any, are intentionally absent from the sequence counter rather than reported as drops? 4. Sequence numbers and loss detection The global_seq_num documentation requires message version greater than 4. Is that field guaranteed for descendants-client lifecycle messages? Do notifications concerning the calling observer and its descendants use the same per-client sequence? How can a client establish a valid initial baseline and detect loss before its first received message? Is every dropped subscribed, unmuted lifecycle event reflected in the next delivered sequence number? What counter reset, wraparound or client-recreation rules must be handled? Would the proposed registry rule make terminal loss fail safely—for example, a lost final exit leaves a process registered—under the supported ordering and visibility semantics? Or is there a counterexample in which the registry can become empty while an unobserved descendant survives? 5. Synchronization, observer failure and delegated work Does es_sync_client provide any loss/completeness information beyond draining preceding queued messages? Its documented callbacks also run for a destroyed or null client, so we would not interpret callback arrival alone as successful completion. Is there a supported mechanism to distinguish a healthy drain from invalidation? What does “instigates” cover for this client? In particular, can it observe or attribute work executed by existing launchd/XPC services, or by unrelated processes receiving file descriptors? We would treat such work as outside a lineage-only closure claim unless it is explicitly covered or independently excluded. Does this client provide any supported protection against a same-UID workload stopping, killing or otherwise interfering with its observer, or must that isolation be supplied separately? Observer failure would invalidate the run; we are not assuming ES supplies a write barrier for evidence files. 6. Supported cleanup and deployment Is there a supported public mechanism to signal a non-child descendant by process-lifetime identity, without a PID-reuse race between observing it and sending a signal? Is there a recommended approach if the observer cannot wait on that process? We do not want to depend on private libproc functions as an application contract. Finally, is this use case eligible for com.apple.developer.endpoint-security.client in a standalone signed command-line observer, and what supported signing/provisioning or packaging requirements apply? This is a request for guidance, not an entitlement application. Our central question is whether supported APIs can establish complete descendant-process closure under these constraints. If they cannot, we would appreciate a clear statement of that limitation or a supported alternative. Thank you. Documentation consulted: es_new_descendants_client es_sync_client global_seq_num es_process_t
2
0
58
1h
TestFlight builds expired across multiple apps; new builds cannot be installed (“Requested app is not available or doesn’t exist”)
Hi, I’m experiencing a TestFlight issue affecting multiple apps in my account. Issue summary: • Several TestFlight builds across all of my apps expired at the same time. • After uploading new replacement builds, neither I nor my testers are able to install them. • Installation fails with the message: “Could not install {App Name}. The requested app is not available or doesn’t exist.” • The build shows as processed and available in App Store Connect. • Testers are already invited and active. • No redeem code is required. I am seeing the same issue on my own device as well. What I’ve tried: • Uploading new builds (incremented version + build number). • Confirmed builds are visible and available in App Store Connect. • Removing and re-adding testers. • Logging out of the app. • Deleting the app from the device. • Restarting the device. • Reinstalling directly from TestFlight. • Restarting TestFlight. Despite this, installation consistently fails with the “requested app is not available or doesn’t exist” error. Expected behavior: • New TestFlight builds should be installable once processed and available. • Testers (and the developer) should be able to install directly from TestFlight. • Expired builds should not block installation of newly uploaded builds. Additional context: • This started immediately after multiple TestFlight builds expired across my apps. • All affected apps were previously installing and testing without issue. • Apple Developer Support has been contacted, but I wanted to check whether others are seeing the same behavior or if there is a known workaround. Has anyone else encountered TestFlight builds becoming unavailable across multiple apps at once, or an install failure after replacing expired builds
78
5
5.8k
2h
Kernel panic "m->m_flags & M_PKTHDR" in uipc_mbuf.c on SMB clients over 10 GbE (macOS 26)
We have a group of Macs that mount SMB shares over 10 GbE with jumbo frames (MTU 9000). Since late June, they have been kernel panicking several times a day with the same assertion: panic(cpu N caller ...): assertion failed: m->m_flags & M_PKTHDR, file: .../xnu/bsd/kern/uipc_mbuf.c, line: 4839 @uipc_socket.c:8260 Panicked thread: dlil_input_en0 Last started kext: com.apple.filesystems.smbfs 6.0.1 Environment Clients: Mac Studio (M1 Max and M1 Ultra) and Mac Pro (2019, Intel with T2), using the built-in 10GBASE-T at MTU 9000 macOS 26.5.1 (25F80), 26.6.2 (25G83) and 26.7 (25G229); it panics on all three Servers: Samba-based NAS, SMB 3.1.1, signing on, encryption off Filed as FB24912731 What we've found It still panics with our third-party EDR fully uninstalled. The Mac that panics needs an active SMB session. A Mac left on the network without a share mounted stayed up through several events that took down the others. Panics are often simultaneous across machines: two to six Macs, with different hardware and different macOS builds, within the same minute. It doesn't need sustained heavy throughput. Some panics came within minutes of reconnecting, during light editing. Setting kern.skywalk.flowswitch.rx_agg_tcp_host=0 did not help. The switch and server links stay up, and spanning tree doesn't change during these events. Only the Macs' ports drop. In one server-side capture, the client stopped sending within about 0.2 ms of receiving a READ response made of 8948-byte frames. That fits the panicked thread being dlil_input. Two existing threads look related Kernel panic using Vagrant synced folders via NFS beginning with macOS 15.4 (FB17853906). A DTS reply there said the issue is in kernel mbuf management and that SMB "is very likely to experience a similar panic." Incorrect packet handling in SMBClient MacOS 26, which describes a race in SMBClient under heavy load above about 10 Gbps. Questions Is this the same underlying issue as FB17853906, and is a fix planned for macOS 26? Our 2019 Mac Pros can't move to a later major release. Is there a known workaround, such as a sysctl, an nsmb.conf option, or a change to MTU or offload settings? Is there logging or a diagnostic we can leave enabled to capture more state at panic time? We can't reproduce this on demand, but between several machines we see it multiple times a day. We can provide full panic reports, sysdiagnoses, and packet captures from both client and server sides.
5
0
400
2h
Adding MCP and connector support to your own Foundation Models apps
Circling back on the LocalLM Lab arc. With v0.7, we've moved from prompt experimentation into real app development on Apple's Foundation Models local AI. The LocalLM Lab SDK lets you build that same on-device model and MCP client this thread has covered directly into your own app, with real tool and data access (Slack, Todoist, GitHub, Notion, Linear, plus Calendar, Reminders, Contacts and Location). And you can ship your app including through the Mac App Store. This is a big improvement over version 0.6, where the localai-cli toolkit needed LocalLM Lab installed and running. On the other hand, the SDK (LocalLMLabSDKCore) doesn't relay through anything; it links FoundationModels and a real MCP client directly into your own binary and is totally self-contained. The example included in the SDK, Plate Today, has actually been built into a sandboxed test app and verified working, with a signed path to a Mac App Store .pkg (Apple Distribution signing + provisioning profile pipeline). That's "verified signable and sandbox-compatible," to be precise. Entitlements (from personal experience: always a complicated topic): com.apple.security.app-sandbox + com.apple.security.network.client for the app itself, plus the standard personal-information entitlements per connector used (com.apple.security.personal-information.calendars, .addressbook, .location) and matching NS*UsageDescription strings in Info.plist. The one worth flagging specifically: the network entitlement is easy to miss and fails silently rather than throwing. Without it, MCP connections and Weather calls just hang with no error surfaced. OAuth handling requires the app delegate callback (application(_:open:)), not SwiftUI's .onOpenURL. Worth knowing before wiring it up if you're SwiftUI-only. Full entitlements list + SDK guide: https://github.com/ancientcomputing/locallm/blob/main/docs/sdk-guide.md Feature page: thisbrain.ai/locallm/sdk.html I hope the availability of the SDK (free, Apache 2.0 license) will give folks further incentive to explore local AI-enabled applications on the Mac. What else would you want to do that the SDK doesn't currently support? File picker? Calendar/Reminders/Contacts edits & writes?
6
1
1.7k
2h
JEV
(I don't follow the AI stuff here, so sorry if this is a stupid question. Or the wrong category.) There is a new fangled AI mode called JEV. Can the current Apple Intelligence libraries do something like it, or is this a WWDC27 thing?
1
0
248
2h
TestFlight blocked since Sept 23: BETA_CONTRACT_MISSING and "The requested app is not available or doesn't exist" (all agreements active)
Since 23 September 2026, TestFlight has stopped working for our app, and nothing on our side fixes it. It looks like the same beta contract problem described in threads 814565 and 821498. App Obaloot: Apple ID 6815224192, bundle ID com.ossaritas.obaloot Version 1.0.0, not released yet (Prepare for Submission) What happened On 23 Sep 2026 at 17:29:53 UTC, builds 1.0.0 (56), (57) and (59) all expired at the same second. Nobody on our team expired them. Builds 56 and 57 had been approved in Beta App Review that same day. Since then, no tester can install any build, internal or external. Builds 60, 94 and 148 process as Valid and are available to our internal group, but tapping Install in TestFlight shows: "Could not install Obaloot. The requested app is not available or doesn't exist." Submitting a build for Beta App Review through the App Store Connect API returns 422 ENTITY_UNPROCESSABLE.BETA_CONTRACT_MISSING: "Beta contract is missing for the app." This happened for build 60 on 23 Sep and build 94 on 24 Sep. Already checked All agreements under Business are Active, nothing is pending, and the membership is active. Test Information (description, feedback email, review contact) and the beta license agreement are filled in. Export compliance is set (no non-exempt encryption). New builds fail the same way. Deleting the app from the device before installing gives the same error. Apple Developer System Status shows no outage. Support Developer Support case: 102974806458 Could someone from the TestFlight team check our team's beta contract and restore it? I'm happy to share any details privately.
1
0
64
2h
Unable to download App Store Connect API keys in iOS Safari
Posting here to see if anyone has found a workaround and/or to get Apple employees' eyes on it. I'm not sure when this bug was introduced but I've found that in Safari on iOS 27, I'm unable to download API keys from App Store Connect. Reported as a Safari bug in Feedback Assistant (FB24994724). I checked web inspector's console and network logs for both my iPad and iPhone; no JS errors and a nondescript network error for the key's fetch request. Google Chrome for iPad/iPhone downloads the .p8 key file without issue, so this feels more like a Safari bug than an App Store Connect bug.
0
0
29
2h
iOS leaves an accessory's no-internet Wi-Fi (NEHotspotConfiguration) for a saved network mid-session
We're building an iOS and Android app that transfers files to and from a device over a Wi-Fi network the device creates. That network has no internet access. The app gets the Wi-Fi credentials from the device (over Bluetooth, or from a QR code on its screen) and joins with NEHotspotConfiguration. Android works reliably. On iOS, partway through a session the phone leaves the device's network and joins a saved network that has internet, which breaks our connection to the device. Setup: iPhone 13 Pro, iOS 26.x NEHotspotConfiguration(ssid:passphrase:isWEP: false) with joinOnce = false. With joinOnce = true, iOS usually stays on the current internet Wi-Fi and never joins the device's network. WPA2. The device is at 192.168.4.1, and its DHCP server hands out the device as router and DNS. Device traffic: NWConnection (TCP) with prohibitedInterfaceTypes = [.cellular]. Server traffic: a separate NWConnection with requiredInterfaceType = .cellular. Wi-Fi Assist is off. Example: we read an 8 MB file from the device (30 s, no problem), then post it to our server over cellular (93 s). During the post, the device connection carries only a small message every ~15 s. 28 s into the post, NWPathMonitor shows Wi-Fi drop out for 3 s, and when it returns the phone is on the our primary network. Occasionally iOS shows a prompt asking whether to stay connected without internet, but usually it switches without asking. We haven't seen it switch during the file read, while the device connection is busy. Questions: Is there a supported way to keep iOS on a device's no-internet network for a whole session? Does traffic on the Wi-Fi interface (such as an active NWConnection) affect whether iOS switches away? Would a DHCP configuration without a router or DNS server change how iOS treats the network? Is joinOnce = false right for this, or can joinOnce = true join when the phone is already on an internet-capable Wi-Fi?
Replies
0
Boosts
0
Views
6
Activity
17m
Auto-generated subtitles not working? (tvOS 27 Beta)
I am testing out the new auto-generated subtitles feature on iOS 27 and tvOS 27. It works on iOS, but not on tvOS. Very same HLS videos. Anyone have any experience with auto-generated subtitles on tvOS 27? AFAICT, there is no special code needed to enable this feature for our apps, correct?
Replies
5
Boosts
1
Views
2.2k
Activity
22m
How to use ClothGrabComponent?
I've simulated a piece of cloth using https://developer.apple.com/documentation/realitykit/physics-cloth-simulation I would like to grab the cloth like what I can in Marvellous Designer. I found the ClothGrabComponent at https://developer.apple.com/documentation/realitykit/clothgrabcomponent However, after I added the ClothGrabComponent to the cloth entity, I am still not able to grab it. Is there any sample code to show me how to grab the cloth? Thank you.
Replies
2
Boosts
0
Views
693
Activity
30m
Supported macOS design for safely terminating an app-owned helper subtree?
I am designing a bounded local diagnostic helper for macOS. It would run only purpose-built helpers supplied by the application, not third-party or untrusted code. The design question is how to stop exactly those helpers and their descendants on timeout, without affecting an unrelated process or incorrectly reporting that cleanup is complete. This is a public-API suitability question, not a report of a reproduced macOS bug. The intended diagnostic is not an antivirus or endpoint-detection product. The required properties are: Identify each owned process by its lifetime and association with this helper run, not a numeric PID or process-group ID alone. Account for descendants across fork/exec, parent exit or reparenting, and process-group/session changes. Observing that a descendant escaped is not equivalent to preventing an escape. Terminate only the still-owned processes without a stale-identity race between checking ownership and signaling. Report completion only when all owned descendants have stopped and no new owned descendants can appear. Leader exit, IPC disconnection, or an unauthenticated empty process list would not be sufficient. Lost events or uncertain membership must leave the outcome inconclusive. Which supported public API or service/containment architecture can provide these properties? If they cannot all be guaranteed, which constraint should be changed and what guarantee can the supported alternative actually provide? I have reviewed the documentation for es_new_descendants_client and es_sync_client. The remaining questions are: Is a descendant-scoped Endpoint Security client appropriate for this non-security-product diagnostic? If so, which documented entitlement and packaging route applies? I am asking about eligibility, not assuming it. Does any supported design combine lifetime-safe control with containment of the whole owned subtree, including concurrent descendant creation? Merely receiving events would not establish that property. What additional protocol, if any, makes a synchronization callback sufficient to establish complete termination when client destruction, event loss, and concurrent activity are possible? I am not treating that callback alone as proof that no owned process remains. I can redesign around a helper that cannot create descendants if that is the supported approach. In that case, what supported mechanism enforces that restriction and what termination guarantees remain? So far, a standalone C harness has passed eleven fabricated-input cases with assertions enabled. It exercised no Endpoint Security client, process-tree creation/enumeration/control, or application behavior. It is not a runtime reproducer for this API-design question and does not establish native lifecycle safety. Pointers to documented guarantees, limitations, or an Apple sample would help me choose the architecture before preparing a narrowly scoped native test. I am not seeking private APIs or a way to disable platform protections. No logs, source archive, or binary is attached.
Replies
1
Boosts
0
Views
76
Activity
1h
navigationTransition in NavigationStack does not work in sheets in iOS 27
navigationTransition(_ style: some NavigationTransition) in NavigationStack does not work in sheets in iOS 27 and iPadOS 27. NavigationTransitions allow a smooth transition from one view to another. An app perfectly working on iOS/iPadOS 26.x does not work correctly on iOS/iPadOS 27.x We have made a simple sample project to show the issue. On 26 OSes there are smooth transitions, on 27.0 when a navigationTransition should occur after a push in the NavigationStack in a sheet, the sheet becomes invisible (the main screen reappears) and suddenly the new view appears without transition. Sample project in Feedback FB24996035 Sample line with the issue SecondPathView(namespace: namespace, path: $path) .navigationTransition(.zoom(sourceID: transitionFromFirstPathId, in: namespace))
Replies
0
Boosts
0
Views
12
Activity
1h
iOS 27: Scroll edge effect region sizes on UIRefreshControl presence, not its height
Summary On iOS 27 the top scroll edge effect of a UITableView is sized around the UIRefreshControl as an edge element, but appears to key on the control's presence in the scroll view rather than its current height. After endRefreshing(), the control collapses to zero height but stays attached, and the effect region keeps reserving a refresh-control's worth of space. The first row stays blurred and dimmed even though it is scrolled fully clear of the navigation bar. Environment iOS 27 (beta), iPhone Xcode 27.0.0 Beta 4 UIKit, UITableView inside a UINavigationController Reproduces with the default edge effect style and with an explicit .soft Steps to reproduce Push a UITableViewController with a UIRefreshControl onto a navigation stack. Ensure content extends under the navigation bar (default for UITableViewController). Pull to refresh and let the refresh end. Observe the first row after the refresh control has retracted. Expected Once the control retracts, the edge effect returns to its pre-pull height and the first row renders crisply. Actual The region stays roughly one refresh-control height too tall and the first row stays blurred. Row positions are unaffected — content offset and adjustedContentInset are correct. Only the extent of the effect is wrong. It corrects itself on the next push/pop. Two probes that isolate it These narrow the cause to the control's presence rather than a general staleness: Re-assigning tableView.topEdgeEffect.style after endRefreshing(), including on a later runloop turn, does NOT correct the region. The style is not what is stale. Detaching the control DOES correct it immediately: tableView.refreshControl = nil So the region is measured from the control being in the hierarchy, and is never re-measured when the control merely collapses. Secondary issue A UIRefreshControl that has been detached is inert if the same instance is re-assigned: tableView.refreshControl = nil tableView.refreshControl = sameInstance // never triggers again A freshly constructed UIRefreshControl must be assigned instead. This is not documented and looks like a second bug. Minimal sample Attached. A UITableViewController with a refresh control and a "Push" bar button that pushes and pops an empty view controller, so the incorrect region and the post-navigation correction can be compared in one run. Related FB20756572 reports the same "edge-effect extent is stale until the next navigation" behaviour for UIScrollEdgeElementContainerInteraction sizing, and notes a change in iOS 27 seed 1. That report received no reply.
Replies
2
Boosts
0
Views
1k
Activity
1h
Cannot run Catalyst app on other devices?!?
I prepare a private project in Xcode, use Archive, Distribute/Copy, save the application somewhere. Copy it to my other computer, run. Works perfectly with normal MacOS applications. With Catalyst ones though it does not; whatever I try, all I get is “The application XXX cannot be opened”. What do I do wrong and how to fix the problem? Thanks!
Replies
0
Boosts
0
Views
17
Activity
1h
Individual account converted to Organization — sole proprietor needs to return to Individual
Hi everyone, I’m looking for advice regarding an Apple Developer Program membership issue. I originally had an Individual membership, which I recently converted to an Organization membership for my business. However, my business is a French micro-entreprise / entreprise individuelle (sole proprietorship). I subsequently discovered that Apple’s documentation states that an individual or sole proprietor/single-person business should enroll as an Individual. The Organization membership is also causing problems with the tax forms because my business is not a separate legal entity from myself. Apple Developer Support confirmed that Organization → Individual conversion is not supported. My app is currently only in TestFlight. It has never been released on the App Store and has no IAP or subscriptions submitted for review. I’m therefore considering creating a new Apple Account and enrolling again in the Apple Developer Program as an Individual, then recreating the app under that account. Has anyone been in this situation? In particular: Can the same person enroll in a new Individual Developer Program membership using a different Apple Account while still being the Account Holder of an existing Organization membership? Are there any identity-verification issues when doing this? Is creating a new Individual membership the recommended solution when an Organization membership cannot be converted back? I already have an open case with Apple Developer Support but haven’t received clarification yet. Thanks for any advice or experience with a similar situation.
Replies
0
Boosts
0
Views
11
Activity
1h
Supported completeness and lifecycle guarantees for es_new_descendants_client
Hello Apple Developer Technical Support, I am evaluating es_new_descendants_client for a local command runner that must report success only after its workload and every process descended from that workload have exited. If observation is incomplete or ambiguous, the runner must report failure. This is a design inquiry, not a report of a reproduced operating-system defect; no entitled prototype has been tested. The proposed observer would create its client and subscribe to lifecycle notifications before launching any workload. It would maintain a registry using process-lifetime identities, add processes on creation and remove them on exit. An unmatched event, missing required field, detected loss or observer failure would invalidate the run. It would consider closure only after all registered workload processes had exited. We have not established that these rules are sufficient. Could you clarify which of the following properties are supported API guarantees, and identify any that applications must not rely on? A documented reference or an explicit statement that a guarantee is unavailable would both help. Please identify applicable macOS/SDK versions and any known version-dependent limitations. 1. Membership and creation-event coverage Does the observed subtree retain a process and all of its future descendants after its original parent exits, it is reparented, it double-forks, or it changes process group/session with setpgid or setsid? Could a process remain observable for exit while creation events for its children become invisible? For a workload launched after successful subscription, does every successful process-creation path—including fork, vfork and posix_spawn—produce a lifecycle event sufficient to register the new process before closure can be declared? Which event and identity fields should be used for each path, including a child that exits without a successful exec? Does the calling observer receive the necessary event for its own initial workload launch? 2. Ordering and the meaning of exit Is there a supported per-client ordering guarantee that every child-creation event from a process is delivered before that process's exit notification, including concurrent creation and exit? Can the child's events arrive before the event that introduces that child? Please distinguish kernel enqueue order, handler delivery order and any processing order the application must impose. At what lifecycle boundary is ES_EVENT_TYPE_NOTIFY_EXIT generated? Does it establish that the identified process can no longer execute or initiate writes, or can relevant activity continue after the notification? We would not equate process exit with filesystem durability or completion of work already delegated to other processes. 3. Muting and other visibility filters Does a newly created descendants client have default process, path or target-path mutes that can suppress fork/exit notifications? What supported sequence of configuration and inspection calls establishes complete lifecycle visibility before launch, including mute inversion and executable-path changes? Apart from subscription and muting, are there policy, security, rate-limit or client-type exclusions that can suppress those events? Which suppressed events, if any, are intentionally absent from the sequence counter rather than reported as drops? 4. Sequence numbers and loss detection The global_seq_num documentation requires message version greater than 4. Is that field guaranteed for descendants-client lifecycle messages? Do notifications concerning the calling observer and its descendants use the same per-client sequence? How can a client establish a valid initial baseline and detect loss before its first received message? Is every dropped subscribed, unmuted lifecycle event reflected in the next delivered sequence number? What counter reset, wraparound or client-recreation rules must be handled? Would the proposed registry rule make terminal loss fail safely—for example, a lost final exit leaves a process registered—under the supported ordering and visibility semantics? Or is there a counterexample in which the registry can become empty while an unobserved descendant survives? 5. Synchronization, observer failure and delegated work Does es_sync_client provide any loss/completeness information beyond draining preceding queued messages? Its documented callbacks also run for a destroyed or null client, so we would not interpret callback arrival alone as successful completion. Is there a supported mechanism to distinguish a healthy drain from invalidation? What does “instigates” cover for this client? In particular, can it observe or attribute work executed by existing launchd/XPC services, or by unrelated processes receiving file descriptors? We would treat such work as outside a lineage-only closure claim unless it is explicitly covered or independently excluded. Does this client provide any supported protection against a same-UID workload stopping, killing or otherwise interfering with its observer, or must that isolation be supplied separately? Observer failure would invalidate the run; we are not assuming ES supplies a write barrier for evidence files. 6. Supported cleanup and deployment Is there a supported public mechanism to signal a non-child descendant by process-lifetime identity, without a PID-reuse race between observing it and sending a signal? Is there a recommended approach if the observer cannot wait on that process? We do not want to depend on private libproc functions as an application contract. Finally, is this use case eligible for com.apple.developer.endpoint-security.client in a standalone signed command-line observer, and what supported signing/provisioning or packaging requirements apply? This is a request for guidance, not an entitlement application. Our central question is whether supported APIs can establish complete descendant-process closure under these constraints. If they cannot, we would appreciate a clear statement of that limitation or a supported alternative. Thank you. Documentation consulted: es_new_descendants_client es_sync_client global_seq_num es_process_t
Replies
2
Boosts
0
Views
58
Activity
1h
Formatting test - please ignore
linkify probe
Replies
3
Boosts
0
Views
29
Activity
2h
TestFlight builds expired across multiple apps; new builds cannot be installed (“Requested app is not available or doesn’t exist”)
Hi, I’m experiencing a TestFlight issue affecting multiple apps in my account. Issue summary: • Several TestFlight builds across all of my apps expired at the same time. • After uploading new replacement builds, neither I nor my testers are able to install them. • Installation fails with the message: “Could not install {App Name}. The requested app is not available or doesn’t exist.” • The build shows as processed and available in App Store Connect. • Testers are already invited and active. • No redeem code is required. I am seeing the same issue on my own device as well. What I’ve tried: • Uploading new builds (incremented version + build number). • Confirmed builds are visible and available in App Store Connect. • Removing and re-adding testers. • Logging out of the app. • Deleting the app from the device. • Restarting the device. • Reinstalling directly from TestFlight. • Restarting TestFlight. Despite this, installation consistently fails with the “requested app is not available or doesn’t exist” error. Expected behavior: • New TestFlight builds should be installable once processed and available. • Testers (and the developer) should be able to install directly from TestFlight. • Expired builds should not block installation of newly uploaded builds. Additional context: • This started immediately after multiple TestFlight builds expired across my apps. • All affected apps were previously installing and testing without issue. • Apple Developer Support has been contacted, but I wanted to check whether others are seeing the same behavior or if there is a known workaround. Has anyone else encountered TestFlight builds becoming unavailable across multiple apps at once, or an install failure after replacing expired builds
Replies
78
Boosts
5
Views
5.8k
Activity
2h
Kernel panic "m->m_flags & M_PKTHDR" in uipc_mbuf.c on SMB clients over 10 GbE (macOS 26)
We have a group of Macs that mount SMB shares over 10 GbE with jumbo frames (MTU 9000). Since late June, they have been kernel panicking several times a day with the same assertion: panic(cpu N caller ...): assertion failed: m->m_flags & M_PKTHDR, file: .../xnu/bsd/kern/uipc_mbuf.c, line: 4839 @uipc_socket.c:8260 Panicked thread: dlil_input_en0 Last started kext: com.apple.filesystems.smbfs 6.0.1 Environment Clients: Mac Studio (M1 Max and M1 Ultra) and Mac Pro (2019, Intel with T2), using the built-in 10GBASE-T at MTU 9000 macOS 26.5.1 (25F80), 26.6.2 (25G83) and 26.7 (25G229); it panics on all three Servers: Samba-based NAS, SMB 3.1.1, signing on, encryption off Filed as FB24912731 What we've found It still panics with our third-party EDR fully uninstalled. The Mac that panics needs an active SMB session. A Mac left on the network without a share mounted stayed up through several events that took down the others. Panics are often simultaneous across machines: two to six Macs, with different hardware and different macOS builds, within the same minute. It doesn't need sustained heavy throughput. Some panics came within minutes of reconnecting, during light editing. Setting kern.skywalk.flowswitch.rx_agg_tcp_host=0 did not help. The switch and server links stay up, and spanning tree doesn't change during these events. Only the Macs' ports drop. In one server-side capture, the client stopped sending within about 0.2 ms of receiving a READ response made of 8948-byte frames. That fits the panicked thread being dlil_input. Two existing threads look related Kernel panic using Vagrant synced folders via NFS beginning with macOS 15.4 (FB17853906). A DTS reply there said the issue is in kernel mbuf management and that SMB "is very likely to experience a similar panic." Incorrect packet handling in SMBClient MacOS 26, which describes a race in SMBClient under heavy load above about 10 Gbps. Questions Is this the same underlying issue as FB17853906, and is a fix planned for macOS 26? Our 2019 Mac Pros can't move to a later major release. Is there a known workaround, such as a sysctl, an nsmb.conf option, or a change to MTU or offload settings? Is there logging or a diagnostic we can leave enabled to capture more state at panic time? We can't reproduce this on demand, but between several machines we see it multiple times a day. We can provide full panic reports, sysdiagnoses, and packet captures from both client and server sides.
Replies
5
Boosts
0
Views
400
Activity
2h
Adding MCP and connector support to your own Foundation Models apps
Circling back on the LocalLM Lab arc. With v0.7, we've moved from prompt experimentation into real app development on Apple's Foundation Models local AI. The LocalLM Lab SDK lets you build that same on-device model and MCP client this thread has covered directly into your own app, with real tool and data access (Slack, Todoist, GitHub, Notion, Linear, plus Calendar, Reminders, Contacts and Location). And you can ship your app including through the Mac App Store. This is a big improvement over version 0.6, where the localai-cli toolkit needed LocalLM Lab installed and running. On the other hand, the SDK (LocalLMLabSDKCore) doesn't relay through anything; it links FoundationModels and a real MCP client directly into your own binary and is totally self-contained. The example included in the SDK, Plate Today, has actually been built into a sandboxed test app and verified working, with a signed path to a Mac App Store .pkg (Apple Distribution signing + provisioning profile pipeline). That's "verified signable and sandbox-compatible," to be precise. Entitlements (from personal experience: always a complicated topic): com.apple.security.app-sandbox + com.apple.security.network.client for the app itself, plus the standard personal-information entitlements per connector used (com.apple.security.personal-information.calendars, .addressbook, .location) and matching NS*UsageDescription strings in Info.plist. The one worth flagging specifically: the network entitlement is easy to miss and fails silently rather than throwing. Without it, MCP connections and Weather calls just hang with no error surfaced. OAuth handling requires the app delegate callback (application(_:open:)), not SwiftUI's .onOpenURL. Worth knowing before wiring it up if you're SwiftUI-only. Full entitlements list + SDK guide: https://github.com/ancientcomputing/locallm/blob/main/docs/sdk-guide.md Feature page: thisbrain.ai/locallm/sdk.html I hope the availability of the SDK (free, Apache 2.0 license) will give folks further incentive to explore local AI-enabled applications on the Mac. What else would you want to do that the SDK doesn't currently support? File picker? Calendar/Reminders/Contacts edits & writes?
Replies
6
Boosts
1
Views
1.7k
Activity
2h
JEV
(I don't follow the AI stuff here, so sorry if this is a stupid question. Or the wrong category.) There is a new fangled AI mode called JEV. Can the current Apple Intelligence libraries do something like it, or is this a WWDC27 thing?
Replies
1
Boosts
0
Views
248
Activity
2h
TestFlight blocked since Sept 23: BETA_CONTRACT_MISSING and "The requested app is not available or doesn't exist" (all agreements active)
Since 23 September 2026, TestFlight has stopped working for our app, and nothing on our side fixes it. It looks like the same beta contract problem described in threads 814565 and 821498. App Obaloot: Apple ID 6815224192, bundle ID com.ossaritas.obaloot Version 1.0.0, not released yet (Prepare for Submission) What happened On 23 Sep 2026 at 17:29:53 UTC, builds 1.0.0 (56), (57) and (59) all expired at the same second. Nobody on our team expired them. Builds 56 and 57 had been approved in Beta App Review that same day. Since then, no tester can install any build, internal or external. Builds 60, 94 and 148 process as Valid and are available to our internal group, but tapping Install in TestFlight shows: "Could not install Obaloot. The requested app is not available or doesn't exist." Submitting a build for Beta App Review through the App Store Connect API returns 422 ENTITY_UNPROCESSABLE.BETA_CONTRACT_MISSING: "Beta contract is missing for the app." This happened for build 60 on 23 Sep and build 94 on 24 Sep. Already checked All agreements under Business are Active, nothing is pending, and the membership is active. Test Information (description, feedback email, review contact) and the beta license agreement are filled in. Export compliance is set (no non-exempt encryption). New builds fail the same way. Deleting the app from the device before installing gives the same error. Apple Developer System Status shows no outage. Support Developer Support case: 102974806458 Could someone from the TestFlight team check our team's beta contract and restore it? I'm happy to share any details privately.
Replies
1
Boosts
0
Views
64
Activity
2h
Unable to download App Store Connect API keys in iOS Safari
Posting here to see if anyone has found a workaround and/or to get Apple employees' eyes on it. I'm not sure when this bug was introduced but I've found that in Safari on iOS 27, I'm unable to download API keys from App Store Connect. Reported as a Safari bug in Feedback Assistant (FB24994724). I checked web inspector's console and network logs for both my iPad and iPhone; no JS errors and a nondescript network error for the key's fetch request. Google Chrome for iPad/iPhone downloads the .p8 key file without issue, so this feels more like a Safari bug than an App Store Connect bug.
Replies
0
Boosts
0
Views
29
Activity
2h
Test post - removed
Removed.
Replies
0
Boosts
0
Views
25
Activity
3h
ZTITLE ZTITLEU ]]> & test
ZBTEXT <u>ZBTEXTU</u>
Replies
0
Boosts
0
Views
24
Activity
3h
Test post - removed
Removed.
Replies
0
Boosts
0
Views
20
Activity
3h
Test post - removed
Removed.
Replies
0
Boosts
0
Views
20
Activity
3h