Posts under App & System Services topic

Post

Replies

Boosts

Views

Activity

App Store Server API mass renewal date extension remains incomplete for 11 days
Hello, I submitted a mass subscription renewal date extension request using the App Store Server API on September 9, 2026. The request was accepted successfully. However, when I check the request using getStatusOfSubscriptionRenewalDateExtensions, the status continues to return: complete: false As of September 20, the request has remained incomplete for 11 days. Request details: Extension: 1 day Reason: temporary service interruption Environment: Production The documentation states that a mass renewal date extension may take hours or even days to complete, but I have not been able to find guidance for a request that remains incomplete this long. Only three subscribers were affected by the service interruption, and I have their originalTransactionId values. I am considering using the individual subscription renewal date extension API instead. My questions are: Is it expected for a mass renewal date extension request to remain complete: false for 11 days? Could this mass request still complete at a later date? Is there any way to cancel or determine whether this mass request is stuck? If I extend the three affected subscriptions individually now, is there a risk that the pending mass request could later complete and extend them a second time? I would like to compensate the affected subscribers as soon as possible while avoiding duplicate extensions. Thank you for any guidance.
0
0
282
1w
iOS 26.4 asks for Face ID instead of Screen Time passcode when disabling Screen Time access for an app
On iOS 26.4, I set a Screen Time passcode. However, when I go to Settings > Apps > [Our App] and turn off Screen Time Access for the app, the system asks for Face ID instead of the Screen Time passcode. As a result, Screen Time access can be disabled without entering the Screen Time passcode. Steps to Reproduce 1. Set a Screen Time passcode on iOS 26.4. 2. Open Settings > Apps > [Our App]. 3. Turn off Screen Time Access for the app. Expected Result The system should require the Screen Time passcode before allowing Screen Time access to be disabled. Actual Result The system asks for Face ID instead of the Screen Time passcode, and Screen Time access is disabled.
14
3
2.5k
1w
How does font caching / resources for each app work?
I'm a font developer. In the development process, I will revise a font and overwrite the OTF file that is currently enabled (registered) with macOS. If I then launch an app, it will immediately use the revised version of the font; while apps that are already loaded will continue to use the old version. This suggests that each app is loading new and separate font data, rather than getting it from some existing cache in memory. Yet macOS does have a "font cache" of some sort. Some apps, like TextEdit, seem to only load the fonts that they need to use. However, other apps, like Pages, load every enabled (registered) font on the OS!! (According to the Open Files list in Activity Monitor.) Given that /System/Library/Fonts/ is 625 Mb, and we can't disable any of it, isn't that a lot of data to be repeating? How many fonts is too many fonts? I can't find much documentation about the process.
7
0
1.8k
1w
What is the supported DriverKit Stop/drain sequence for an IOUserClient operation queue?
Environment: macOS 26.6.2 (25G83), Apple silicon Xcode 26.6 (17F113) DriverKit SDK 25.5 I am implementing a DriverKit IOService with an IOUserClient. This is a lifecycle and object-ownership question independent of the device protocol. The intended design admits at most one user client during a provider lifetime. Lifecycle methods run on the provider’s default queue, while IOUserClient ExternalMethod requests run on a separate serial IODispatchQueue. At most one device request may be in flight. The shutdown invariant we need is: Stop accepting new requests. Allow every accepted request to complete exactly once, or cancel it. Observe completion of the operation queue’s cancellation handler. Call the inherited Stop implementation last. Perform no provider access afterward. The relevant public documentation is: IOService::Stop: https://developer.apple.com/documentation/driverkit/ioservice/stop IODispatchQueue::Cancel: https://developer.apple.com/documentation/driverkit/iodispatchqueue/cancel IOService::SetDispatchQueue: https://developer.apple.com/documentation/driverkit/ioservice/setdispatchqueue For the normal path, the proposed sequence is conceptually: Stop(provider): close request admission operationQueue->Cancel(cancellationHandler) wait for the cancellation handler from the separate queue super::Stop(provider) I need clarification of the complete supported public API contract: If IODispatchQueue::Cancel returns a non-success result, is its cancellation handler still guaranteed to execute? If it is not, what supported action lets Stop keep the provider and user client valid until previously accepted work is no longer capable of accessing them? Is it supported for the provider and its one user client to share the provider-owned serial operation queue? If the IOUserClient stops independently, must it own and cancel a separate queue, or is there a supported per-client drain mechanism that does not cancel provider-owned work? Is the driver’s public IOService::Stop override guaranteed to run on every termination path where accepted user-client work must be drained, including when the provider is already inactive or the DriverKit server has slept? If not, which public lifecycle callback supplies that drain point? Is blocking the provider’s default queue inside Stop while awaiting the cancellation handler from a separate operation queue the supported interpretation of “wait for your cancellation handlers”? If not, what public continuation mechanism should be used before calling inherited Stop? We also observed one power-management panic after sleep/wake: HiMDScsiDriver::setPowerState(..., 0 -> 4) timed out after 20342 ms The DEXT does not currently override SetPowerState. This panic motivates the lifecycle review, but I am not treating it as proof that the Stop/drain design caused the timeout. I am looking specifically for a supported public DriverKit sequence. I do not want to rely on private framework entry points or infer object-lifetime guarantees from a successful build or experiment.
4
0
1k
1w
iOS 27: CPNowPlayingTemplate does not follow the active Now Playing client between an app's own client and its ApplicationMusicPlayer client (FB24840951)
On iOS 27, an app of mine that plays both its own audio and Apple Music tracks has two Now Playing clients in MediaRemote, as any app using ApplicationMusicPlayer.shared does: its own process's MPNowPlayingInfoCenter.default(), and MusicKit's player hosted out of process by com.apple.MediaPlayer.RemotePlayerService. MediaRemote elects between them correctly - the client whose process is making sound becomes active - and both the Lock Screen and the CarPlay dashboard follow the change. My CPNowPlayingTemplate does not. It stays on whichever client it was on when the change happened, so during an Apple Music track the car shows my own (now stale) entry with the clock frozen and a play glyph while music is audible; in some sessions the reverse, where my own audio after a track gets a blank template whose play presses are delivered to MusicKit's empty player and interrupt playback. From mediaremoted on iOS 27, handlePlaybackQueueRequest from CarPlayTemplateUIHost returns for (pid) > default throughout a track, and no contentItemChange for the RemotePlayerService path is ever posted to CarPlayTemplateUIHost, though it is posted to springboard, CarPlayApp and MediaRemoteUI. On iOS 26.6.1 with the same build, the same template host reads and commands RemotePlayerService/ during the track and > default afterwards. So the routing of commands to the active client is not what changed - what the template reads and sends to is. Filed as FB24840951 with mediaremoted captures from both OS versions, full sysdiagnose archives and screen recordings of the car screen beside the Lock Screen. Two questions: Is there a supported way for an audio app to tell CPNowPlayingTemplate which of its Now Playing clients to display? MPNowPlayingSession looks like the intended mechanism but accepts only AVPlayer instances, so it cannot represent either an AVAudioEngine graph or MusicKit's player; tested with a dormant AVPlayer it reported isActive == true every time and moved the template on some tracks and not others. Does the new MiniPlayer affect this? WWDC26's "Rev up your CarPlay app" says the MiniPlayer is new in iOS 27 and appears automatically for every app that shows now playing. Since the template was reworked in the same release this regressed in, does CPNowPlayingTemplate.shared.allowsMiniPlayer = false change which client is read? I have not tested it yet and will report back either way. Meanwhile the only thing that moves the car is republishing my own entry once a second as a new content item, which the template does re-read, so the clock steps instead of freezing. That ships in PodMelody 1.1.4, a workaround for an OS bug rather than a fix - and it doesn't resolve the mismatched play/pause glyph. If you have an audio app using ApplicationMusicPlayer and CarPlay, I would be glad to know whether you see the same thing, and in which car - duplicates on the Feedback are what get these prioritised.
0
0
155
1w
watchOS 27: Environmental Audio Exposure sampling became extremely sparse
After updating my Apple Watch Series 10 to the public release of watchOS 27, Environmental Sound Level measurements became extremely sparse. Before watchOS 27, with Environmental Sound Measurements enabled, my watch recorded environmental sound data approximately every 30 seconds and the coverage was nearly continuous throughout the day. After updating the same Apple Watch to watchOS 27, the behavior changed significantly: Environmental Sound Level samples are much less frequent Large gaps appear between measurements Overall daily temporal coverage is dramatically reduced The same change is visible both in the Health app and through HealthKit using HKQuantityTypeIdentifier.environmentalAudioExposure No relevant settings were changed, and Environmental Sound Measurements are still enabled. This is important for apps that use Environmental Audio Exposure data for time-based analysis. In my case, I use this data for sleep and nap environment analysis. With the much sparser sampling on watchOS 27, it is difficult to reliably evaluate the acoustic environment during a specific sleep period. I have also seen other watchOS 27 users reporting similar behavior: https://www.reddit.com/r/watchOSBeta/comments/1wjrdaq/watchos_27_broke_the_noise_monitoring_app/ I submitted a Feedback Assistant report: FB24837491 Has anyone else observed the same change on watchOS 27? I’m especially interested in whether this is: an intentional change to the sampling or aggregation strategy, a HealthKit write-frequency change, or a regression in watchOS 27. If anyone has compared HKQuantitySample.startDate, endDate, sample duration, and sample interval before and after the watchOS 27 update, that data would be very useful for comparison.
0
1
159
1w
Matter device shows “Uncertified Accessory” in Apple Home despite CSA certification and DCL listing (OEM/ODM, Portfolio Family CD)
Hello Apple Home/Matter team, our Matter product is CSA-certified, has a valid CD, and is listed in Compliance DCL. In testing with HomePod mini as border router, commissioning proceeds but Apple Home still shows “Uncertified Accessory.” We are an OEM/ODM manufacturer: product vendor_id/product_id belong to the brand owner, while dac_origin_vendor_id/dac_origin_product_id belong to us(manufacturer). The device also uses the brand owner’s product VID/PID at runtime. Our certification is Portfolio Family, so CD product_id is an array covering 6 SKUs. Is this model expected to pass Apple Home certification checks, and what are the most common causes of this warning? Emma
1
1
401
1w
IOConnectMapMemory questions
I am developing a dext that is running into issues pertaining to IOConnectMapMemory (at least I think so). There are 3 parts of code that are involved, the dext (which allocates the memory in the first place), a user client library which is involved in connecting to the dext and releasing when the hardware is removed, and finally some processing code (at the user level) which executes on this shared block of memory from the dext. The shared memory is allocated using an IOBufferMemoryDescriptor: IOBufferMemoryDescriptor::Create(kIOMemoryDirectionNone, sizeof(sharedMemoryBlock), IOVMPageSize, &(ivars->mSharedMemoryBlockMemDesc)); The User Client Library acquires a mapped pointer to this memory by calling IOConnectMapMemory: IOConnectMapMemory(mConnect, kMemoryType_SharedMemoryBlock, mach_task_self(), (mach_vm_address_t*)&mUserClientSharedBlockPtr, (mach_vm_size_t*)&mSizeOfUserClientSharedBlock, kIOMapAnywhere); …which triggers the dext’s IOUserClient subclass' “CopyClientMemoryForType_Impl”. That code adds a retain and returns a pointer to the IOBufferMemoryDescriptor: case kMemoryType_SharedMemoryBlock: // error checks first (make sure it’s allocated and initialized, etc) ivars->mSharedMemoryBlockMemDesc->retain(); *memory = ivars->mSharedMemoryBlockMemDesc; break; IOConnectMapMemory returns the “mapped pointer” (in mUserClientSharedBlockPtr) to the User Client Library, which in turn provides it to the processing code. The processing code checks the pointer validity, and if valid, runs its processing. This worked fine with a kext implementation. This fails with dext implementation, because during the processing call (after validity check but during usage) the mapped pointer can become NULL, which seems to be against the design pattern, and causes the application to crash due to an access violation (dereferencing NULL). I assume I am doing something incorrect here, but I’m not seeing what it is. The memory was retained, so it should not be deleted until the User Client Library has released it, but the only release available would be IOConnectUnmapMemory, and that fails with “invalid argument” (0xE00002C2) after the device is hot-unplugged. I am not finding IOConnectMapMemory examples on developer.apple.com. I have verified via the forums that IOConnectMapMemory is still a recommended practice with DriverKit development: https://developer.apple.com/forums/thread/803947?answerId=862249022#862249022 . What’s the trick here for stability? The device is a peripheral which can be unplugged or turned off at any time, which would result in the dext and user client library code tearing down the structures and memory, but it should be able to do so safely without causing access violations. (Note, this has been simplified for the purpose of focusing the question, in reality there are 4 separate memory blocks which are shared in this fashion: two ring buffers, main engine status, and client status. They each use their own memory_type definition, but a general solution is needed and can be applied to all 4, and there can be multiple clients at any point in time).
1
0
1.1k
1w
Network UPS?
I found some nice code that implements a NUT client, and now I want to take the next step -- I would like to get it to show up as a UPS for macOS. But I've never done anything with IOKit... and there don't seem to be a lot of examples of, maybe, IOPowerSources?
6
0
464
1w
Crashe__CFRunLoopServiceMachPort.cold 96% Foreground
Hello, we have encountered a large number of __CFRunLoopServiceMachPort.cold crashes on iOS 26. These crashes frequently occur when the app transitions from the background to the foreground or is launched after sitting idle for a period of time. Despite extensive analysis, we have been unable to find a solution. Currently, the crash data indicates that this issue is specific to iOS 26. We would greatly appreciate your assistance. Thank you very much! Hardware Model: iPhone18,1 OS Version: iPhone OS 26.5.2 (23F84) Release Type: User Baseband Version: 1.60.02 Crash Reporter Key: fda96a4036dcb83e124660e11b654c9484b81dae Incident Identifier: EF18C4DD-7624-42D0-BA72-F17BBC263B16 Time Awake Since Boot: 2900000 seconds Triggered by Thread: 0, Dispatch Queue: com.apple.main-thread Exception Type: EXC_BREAKPOINT (SIGTRAP) Exception Codes: 0x0000000000000001, 0x00000001917d316c Termination Reason: Namespace SIGNAL, Code 5, Trace/BPT trap: 5 Terminating Process: exc handler [82210] Application Specific Information: (ipc/rcv) invalid name Thread 0 name: Dispatch queue: com.apple.main-thread Thread 0 Crashed: 0 CoreFoundation 0x1917d316c __CFRunLoopServiceMachPort.cold.1 + 64 1 CoreFoundation 0x19168a444 __CFRunLoopServiceMachPort + 416 2 CoreFoundation 0x191654310 __CFRunLoopRun + 1188 3 CoreFoundation 0x19165354c _CFRunLoopRunSpecificWithOptions + 532 4 GraphicsServices 0x236df7498 GSEventRunModal + 120 5 UIKitCore 0x19734c244 -[UIApplication _run] + 796 6 UIKitCore 0x1972b7158 UIApplicationMain + 332 7 KMMVideo 0x1047fe24c 0x104304000 + 5218892 8 dyld 0x18e261c1c start + 6928 Thread 1 name: transmit_hls_7683_193735 Thread 1: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 libc++.1.dylib 0x1a0d5dbcc std::__1::condition_variable::wait(std::__1::unique_lockstd::__1::mutex&) + 32 3 iOSPlayer 0x118cd6114 a_task_runner::worker() + 116 4 iOSPlayer 0x118cd5650 a_task_runner::work_thread() + 196 5 iOSPlayer 0x118cd654c void* std::__1::__thread_proxy[abi:ne200100]<std::__1::tuple<std::__1::unique_ptr<std::__1::__thread_struct, std::__1::default_deletestd::__1::__thread_struct>, void (a_task_runner::)(), a_task_runner>>(void*) + 72 6 libsystem_pthread.dylib 0x1f0854438 _pthread_start + 136 7 libsystem_pthread.dylib 0x1f08508cc thread_start + 8 Thread 2: 0 libsystem_kernel.dylib 0x2407d9ed8 read + 8 1 XLTranscodeKit 0x115bb5f4c runtime.read_trampoline.abi0 + 28 Thread 3: Thread 4: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 XLTranscodeKit 0x115bb6648 runtime.pthread_cond_wait_trampoline.abi0 + 24 3 XLTranscodeKit 0x115bb4fb8 runtime.asmcgocall.abi0 + 200 4 ??? 0xd65f03c0 ??? Thread 5: 0 XLTranscodeKit 0x115b3eb68 */bytealg.IndexByteString + 40 1 XLTranscodeKit 0x115b966b8 runtime.findnull + 104 Thread 6: 0 libsystem_kernel.dylib 0x2407db8dc kevent + 8 1 XLTranscodeKit 0x115bb6398 runtime.kevent_trampoline.abi0 + 40 Thread 7: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 XLTranscodeKit 0x115bb6648 runtime.pthread_cond_wait_trampoline.abi0 + 24 3 XLTranscodeKit 0x115bb4fb8 runtime.asmcgocall.abi0 + 200 4 ??? 0xd65f03c0 ???
3
0
396
1w
Can an ExtensionFoundation-based extension on macOS have its own extension point and host its own extensions?
It is possible for an extension to an app (based on ExtensionFoundation) to declare its own extension point and host its own ExtensionFoundation extensions? Based on the documentation, I am guessing the answer is no, but worth double-checking. What would be the reason to prevent this? Every ExtensionFoundation extension runs in its own process, and may have need to be extended safely just as its host app does. Thank you!
3
0
224
1w
Removing stale Local Network entries?
Hello, I'm desperately looking for a way to purge the contents of the Local Network allowlist in System Settings. Every version of a test app I've ever used gets an entry in there, and apparently so does each build of Chrome and Claude Code. Claude recommended I include the following context, and if there's a specific answer to that, great, but any way of purging this list would make me very happy. ==== Caution: slop below this line ==== macOS 27.0 (26A428), Apple silicon. The Local Network list has 471 entries, many dead: Chrome code_sign_clone paths that no longer exist, old ad-hoc builds, uninstalled apps. The pane can't remove any. Is there a supported way to remove entries or reset the list, short of Recovery? Editing /Library/Preferences/com.apple.networkextension.plist as root fails with EPERM, both rename-over and open-for-write. New files in that directory work. SIP is on, the file has no flags or xattrs, Full Disk Access didn't help, and there are no Sandbox/TCC denials in the log. What protects this file?
3
0
461
1w
Custom Installer Plugin (x86_64 bundle) is not loaded on macOS 26A428 / 25G229 / 24H23, causing an installer GUI pane to be skipped
Summary A third-party PKG installer that ships a custom Installer Plugin no longer displays one of its selection panes. The plugin bundle appears not to be loaded, so the pane that it provides is silently skipped and the user cannot choose the intended installation option. This behavior started with recent macOS releases and did not occur on the immediately preceding versions, so it looks like a regression. Environment Machine: MacBook Pro 14-inch (M3) Affected builds: macOS 27.0 (26A428) macOS 26.7 (25G229) macOS 15.8 (24H23) Not affected: macOS 26.6 and earlier macOS 15.7 and earlier Reproducibility: every time Plugin binary: Mach-O 64-bit bundle, x86_64 only (no arm64 slice) Steps to Reproduce Download the Epson iProjection Ver.4.04 installer from the vendor support site: https://support.epson.net/setupnavi/?LG2=EN&OSC=MI&PINF=vpapp&MKN=EB-770Fi Mount the downloaded disk image and run the PKG installer. Step through the installer GUI and observe the pane transitions. Expected Result The installer GUI shows the "Application type" selection pane provided by the bundled Installer Plugin. Actual Result The "Application type" pane is never shown. The installer proceeds as if the plugin did not exist, and the user cannot select the installation type. What I Checked 1. The plugin is present inside the PKG pkgutil --expand-full PKG_PATH DEST_DIR The expanded payload contains the plugin bundle and its Mach-O executable under Contents/MacOS. 2. Architecture of the plugin binary file DEST_DIR/PluginName.bundle/Contents/MacOS/PluginName Result: Mach-O 64-bit bundle x86_64. It is a single-architecture binary with no arm64 slice. 3. The plugin is actually touched at install time sudo fs_usage -w -f filesys InstallerRemotePluginService-x86 opens the plugin executable inside the installer's temporary directory (a path under /private/tmp/com.apple.installer* ). So the plugin is reached as a load target, but the pane still does not appear. 4. Code signature validation When the installer is launched directly from the mounted disk image, code signature validation fails with: Too many levels of symbolic links My working theory is that the bundle contents are turned into symbolic links when the plugin is expanded, and that this causes codesign validation to fail, so the plugin is rejected before it can register its pane. 5. Code evaluation by syspolicyd log stream --info --debug --predicate 'process == "syspolicyd"' GK package assessment, GK process assessment and GK performScan entries are present, so Gatekeeper evaluation itself is running. The following also appears: Error Domain=NSOSStatusErrorDomain Code=-67062 Unsigned code in: PST: (path: REDACTED), (team: (null)), (id: (null)), (bundle_id: (null)) The PST path is anonymized in the log, so I could not confirm that this particular assessment refers to the plugin bundle. 6. XProtect evaluation results differ between versions log stream --info --debug --predicate 'process == "syspolicyd"' On the versions where the installer works correctly, the GK Xprotect results lines explicitly include a file URL pointing at the plugin bundle inside the installer temporary directory. On the affected builds, searching the same log for the plugin bundle name returns zero matches. That suggests the bundle is not being processed as an XProtect evaluation target at all on the newer builds. Question Was there a change in how Installer Plugins are expanded or validated in these releases, in particular around symlinked bundle contents or single-architecture x86_64 plugins? Any guidance on the supported way to ship an Installer Plugin so that it is still loaded on current macOS would be appreciated.
1
0
267
1w
Error Domain=PKPassKitErrorDomain Code=2
We are getting this error frequently and our customers are getting increasing frustrated when they are unable to add their credit card to Apple Wallet. There is no clear explanation on when this error arises. I sincerely request help to understand the cause of this issue. Device info: Apple iOS 26.6.1.
0
0
94
1w
In App Provisioning PKErrorHTTPResponseStatusCodeKey=500
Hello, we are developing in app provisioning of our American Express network cards. After clicking add to apple wallet in our app, I launch the PKAddPaymentPassViewController and click next. It loads for a few seconds and then I get: [<private>] ProvisioningOperationComposer: Step '<private>' failed with error Error Domain=PKProvisioningErrorDomain Code=5 UserInfo={PKErrorHTTPResponseStatusCodeKey=500} Does anyone have any insight on what this error means?
5
1
1.4k
1w
Family Controls authorization error
Hi everyone, I'm developing an iOS app that uses Apple's Family Controls / Screen Time APIs. I've encountered a strange issue when testing with multiple devices: The app works normally on the first device. When I install the same TestFlight build on a second device, the user completes the Family Controls authorization successfully. Immediately after authorization, an error appears: "Family Controls is only available for one application." After dismissing the error, the app still works normally. Screen Time / Shield functionality also appears to work as expected. The issue seems to occur specifically when authorizing the app on a second device. Has anyone encountered this error before?
0
0
75
1w
StoreKit External Purchases or Offers entitlement missing from macOS provisioning profile
Hey We are implementing EU external purchases for both our iOS and native macOS apps as it's written here: https://developer.apple.com/br/support/payment-options-on-the-app-store-in-the-eu For our App ID, we enabled StoreKit External Purchases or Offers, whose entitlement key is: com.apple.developer.storekit.custom-purchase-link.allowed-regions The capability works for iOS, but newly generated macOS provisioning profiles do not contain this entitlement. In Certificates, Identifiers & Profiles, the capability itself shows Platform Support: iOS, tvOS, watchOS, visionOS - macOS is not listed. However, the StoreKit documentation for ExternalPurchaseCustomLink and the EU alternative-payment documentation appear to describe external-purchase support more generally. Could you please clarify: Is com.apple.developer.storekit.custom-purchase-link.allowed-regions currently supported for native macOS apps distributed through the Mac App Store? If not, what entitlement and API should a native macOS app use for EU external purchases and external-purchase token reporting? Is macOS support for the StoreKit External Purchases or Offers entitlement planned or available through a separate entitlement request? At the moment, our macOS provisioning profiles cannot contain this entitlement because macOS is not listed as a supported platform for this capability. Thank you!
0
0
525
1w
[macOS 27] Non-sandboxed Developer ID app blocked from accessing Chrome and Firefox directories under ~/Library/Application Support/ — intentional TCC change?
Environment: App: Developer ID signed, non-sandboxed macOS app Browsers affected: Google Chrome, Mozilla Firefox Safari: Working fine on macOS 27 Working on: macOS 26 and earlier Broken on: macOS 27 (Golden Gate) Issue Our non-sandboxed, Developer ID signed macOS app interacts with Chrome and Firefox directories under ~/Library/Application Support/ as part of its browser extension deployment workflow. On macOS 26 and earlier, this worked without any special permissions. On macOS 27, the same operations are silently blocked — no TCC prompt is shown to the user, access is simply denied. Granting Full Disk Access to our app via System Settings > Privacy & Security > Full Disk Access resolves the issue completely on macOS 27. Safari is unaffected — our Safari extension is bundled directly inside our app and continues to work correctly on macOS 27 without any additional permissions. Question Has macOS 27 intentionally introduced TCC or MACL-based protection over Chrome and Firefox directories under ~/Library/Application Support/, blocking access from non-owner processes including non-sandboxed Developer ID apps? If this is an intentional change, is Full Disk Access the expected requirement going forward, or is there a more targeted entitlement or Apple-recommended approach for a non-sandboxed app that legitimately needs to access browser directories as part of an extension deployment workflow?
1
0
240
1w
ipadOS27でのpower supply問題
一部のiPadで電源が0%になるとどの充電器でも1%までおおよそ9時間もかかります
Replies
0
Boosts
0
Views
278
Activity
1w
App Store Server API mass renewal date extension remains incomplete for 11 days
Hello, I submitted a mass subscription renewal date extension request using the App Store Server API on September 9, 2026. The request was accepted successfully. However, when I check the request using getStatusOfSubscriptionRenewalDateExtensions, the status continues to return: complete: false As of September 20, the request has remained incomplete for 11 days. Request details: Extension: 1 day Reason: temporary service interruption Environment: Production The documentation states that a mass renewal date extension may take hours or even days to complete, but I have not been able to find guidance for a request that remains incomplete this long. Only three subscribers were affected by the service interruption, and I have their originalTransactionId values. I am considering using the individual subscription renewal date extension API instead. My questions are: Is it expected for a mass renewal date extension request to remain complete: false for 11 days? Could this mass request still complete at a later date? Is there any way to cancel or determine whether this mass request is stuck? If I extend the three affected subscriptions individually now, is there a risk that the pending mass request could later complete and extend them a second time? I would like to compensate the affected subscribers as soon as possible while avoiding duplicate extensions. Thank you for any guidance.
Replies
0
Boosts
0
Views
282
Activity
1w
iOS 26.4 asks for Face ID instead of Screen Time passcode when disabling Screen Time access for an app
On iOS 26.4, I set a Screen Time passcode. However, when I go to Settings > Apps > [Our App] and turn off Screen Time Access for the app, the system asks for Face ID instead of the Screen Time passcode. As a result, Screen Time access can be disabled without entering the Screen Time passcode. Steps to Reproduce 1. Set a Screen Time passcode on iOS 26.4. 2. Open Settings > Apps > [Our App]. 3. Turn off Screen Time Access for the app. Expected Result The system should require the Screen Time passcode before allowing Screen Time access to be disabled. Actual Result The system asks for Face ID instead of the Screen Time passcode, and Screen Time access is disabled.
Replies
14
Boosts
3
Views
2.5k
Activity
1w
Does Apple provide something by which an app can be excluded from receiving gamepad inputs?
We can give permission to app for Mic and Camera. Can we build something by which an app doesn't get permission to receive any gamepad inputs but other app that have permission work regularly.
Replies
0
Boosts
0
Views
86
Activity
1w
How does font caching / resources for each app work?
I'm a font developer. In the development process, I will revise a font and overwrite the OTF file that is currently enabled (registered) with macOS. If I then launch an app, it will immediately use the revised version of the font; while apps that are already loaded will continue to use the old version. This suggests that each app is loading new and separate font data, rather than getting it from some existing cache in memory. Yet macOS does have a "font cache" of some sort. Some apps, like TextEdit, seem to only load the fonts that they need to use. However, other apps, like Pages, load every enabled (registered) font on the OS!! (According to the Open Files list in Activity Monitor.) Given that /System/Library/Fonts/ is 625 Mb, and we can't disable any of it, isn't that a lot of data to be repeating? How many fonts is too many fonts? I can't find much documentation about the process.
Replies
7
Boosts
0
Views
1.8k
Activity
1w
What is the supported DriverKit Stop/drain sequence for an IOUserClient operation queue?
Environment: macOS 26.6.2 (25G83), Apple silicon Xcode 26.6 (17F113) DriverKit SDK 25.5 I am implementing a DriverKit IOService with an IOUserClient. This is a lifecycle and object-ownership question independent of the device protocol. The intended design admits at most one user client during a provider lifetime. Lifecycle methods run on the provider’s default queue, while IOUserClient ExternalMethod requests run on a separate serial IODispatchQueue. At most one device request may be in flight. The shutdown invariant we need is: Stop accepting new requests. Allow every accepted request to complete exactly once, or cancel it. Observe completion of the operation queue’s cancellation handler. Call the inherited Stop implementation last. Perform no provider access afterward. The relevant public documentation is: IOService::Stop: https://developer.apple.com/documentation/driverkit/ioservice/stop IODispatchQueue::Cancel: https://developer.apple.com/documentation/driverkit/iodispatchqueue/cancel IOService::SetDispatchQueue: https://developer.apple.com/documentation/driverkit/ioservice/setdispatchqueue For the normal path, the proposed sequence is conceptually: Stop(provider): close request admission operationQueue->Cancel(cancellationHandler) wait for the cancellation handler from the separate queue super::Stop(provider) I need clarification of the complete supported public API contract: If IODispatchQueue::Cancel returns a non-success result, is its cancellation handler still guaranteed to execute? If it is not, what supported action lets Stop keep the provider and user client valid until previously accepted work is no longer capable of accessing them? Is it supported for the provider and its one user client to share the provider-owned serial operation queue? If the IOUserClient stops independently, must it own and cancel a separate queue, or is there a supported per-client drain mechanism that does not cancel provider-owned work? Is the driver’s public IOService::Stop override guaranteed to run on every termination path where accepted user-client work must be drained, including when the provider is already inactive or the DriverKit server has slept? If not, which public lifecycle callback supplies that drain point? Is blocking the provider’s default queue inside Stop while awaiting the cancellation handler from a separate operation queue the supported interpretation of “wait for your cancellation handlers”? If not, what public continuation mechanism should be used before calling inherited Stop? We also observed one power-management panic after sleep/wake: HiMDScsiDriver::setPowerState(..., 0 -> 4) timed out after 20342 ms The DEXT does not currently override SetPowerState. This panic motivates the lifecycle review, but I am not treating it as proof that the Stop/drain design caused the timeout. I am looking specifically for a supported public DriverKit sequence. I do not want to rely on private framework entry points or infer object-lifetime guarantees from a successful build or experiment.
Replies
4
Boosts
0
Views
1k
Activity
1w
iOS 27: CPNowPlayingTemplate does not follow the active Now Playing client between an app's own client and its ApplicationMusicPlayer client (FB24840951)
On iOS 27, an app of mine that plays both its own audio and Apple Music tracks has two Now Playing clients in MediaRemote, as any app using ApplicationMusicPlayer.shared does: its own process's MPNowPlayingInfoCenter.default(), and MusicKit's player hosted out of process by com.apple.MediaPlayer.RemotePlayerService. MediaRemote elects between them correctly - the client whose process is making sound becomes active - and both the Lock Screen and the CarPlay dashboard follow the change. My CPNowPlayingTemplate does not. It stays on whichever client it was on when the change happened, so during an Apple Music track the car shows my own (now stale) entry with the clock frozen and a play glyph while music is audible; in some sessions the reverse, where my own audio after a track gets a blank template whose play presses are delivered to MusicKit's empty player and interrupt playback. From mediaremoted on iOS 27, handlePlaybackQueueRequest from CarPlayTemplateUIHost returns for (pid) > default throughout a track, and no contentItemChange for the RemotePlayerService path is ever posted to CarPlayTemplateUIHost, though it is posted to springboard, CarPlayApp and MediaRemoteUI. On iOS 26.6.1 with the same build, the same template host reads and commands RemotePlayerService/ during the track and > default afterwards. So the routing of commands to the active client is not what changed - what the template reads and sends to is. Filed as FB24840951 with mediaremoted captures from both OS versions, full sysdiagnose archives and screen recordings of the car screen beside the Lock Screen. Two questions: Is there a supported way for an audio app to tell CPNowPlayingTemplate which of its Now Playing clients to display? MPNowPlayingSession looks like the intended mechanism but accepts only AVPlayer instances, so it cannot represent either an AVAudioEngine graph or MusicKit's player; tested with a dormant AVPlayer it reported isActive == true every time and moved the template on some tracks and not others. Does the new MiniPlayer affect this? WWDC26's "Rev up your CarPlay app" says the MiniPlayer is new in iOS 27 and appears automatically for every app that shows now playing. Since the template was reworked in the same release this regressed in, does CPNowPlayingTemplate.shared.allowsMiniPlayer = false change which client is read? I have not tested it yet and will report back either way. Meanwhile the only thing that moves the car is republishing my own entry once a second as a new content item, which the template does re-read, so the clock steps instead of freezing. That ships in PodMelody 1.1.4, a workaround for an OS bug rather than a fix - and it doesn't resolve the mismatched play/pause glyph. If you have an audio app using ApplicationMusicPlayer and CarPlay, I would be glad to know whether you see the same thing, and in which car - duplicates on the Feedback are what get these prioritised.
Replies
0
Boosts
0
Views
155
Activity
1w
watchOS 27: Environmental Audio Exposure sampling became extremely sparse
After updating my Apple Watch Series 10 to the public release of watchOS 27, Environmental Sound Level measurements became extremely sparse. Before watchOS 27, with Environmental Sound Measurements enabled, my watch recorded environmental sound data approximately every 30 seconds and the coverage was nearly continuous throughout the day. After updating the same Apple Watch to watchOS 27, the behavior changed significantly: Environmental Sound Level samples are much less frequent Large gaps appear between measurements Overall daily temporal coverage is dramatically reduced The same change is visible both in the Health app and through HealthKit using HKQuantityTypeIdentifier.environmentalAudioExposure No relevant settings were changed, and Environmental Sound Measurements are still enabled. This is important for apps that use Environmental Audio Exposure data for time-based analysis. In my case, I use this data for sleep and nap environment analysis. With the much sparser sampling on watchOS 27, it is difficult to reliably evaluate the acoustic environment during a specific sleep period. I have also seen other watchOS 27 users reporting similar behavior: https://www.reddit.com/r/watchOSBeta/comments/1wjrdaq/watchos_27_broke_the_noise_monitoring_app/ I submitted a Feedback Assistant report: FB24837491 Has anyone else observed the same change on watchOS 27? I’m especially interested in whether this is: an intentional change to the sampling or aggregation strategy, a HealthKit write-frequency change, or a regression in watchOS 27. If anyone has compared HKQuantitySample.startDate, endDate, sample duration, and sample interval before and after the watchOS 27 update, that data would be very useful for comparison.
Replies
0
Boosts
1
Views
159
Activity
1w
Matter device shows “Uncertified Accessory” in Apple Home despite CSA certification and DCL listing (OEM/ODM, Portfolio Family CD)
Hello Apple Home/Matter team, our Matter product is CSA-certified, has a valid CD, and is listed in Compliance DCL. In testing with HomePod mini as border router, commissioning proceeds but Apple Home still shows “Uncertified Accessory.” We are an OEM/ODM manufacturer: product vendor_id/product_id belong to the brand owner, while dac_origin_vendor_id/dac_origin_product_id belong to us(manufacturer). The device also uses the brand owner’s product VID/PID at runtime. Our certification is Portfolio Family, so CD product_id is an array covering 6 SKUs. Is this model expected to pass Apple Home certification checks, and what are the most common causes of this warning? Emma
Replies
1
Boosts
1
Views
401
Activity
1w
IOConnectMapMemory questions
I am developing a dext that is running into issues pertaining to IOConnectMapMemory (at least I think so). There are 3 parts of code that are involved, the dext (which allocates the memory in the first place), a user client library which is involved in connecting to the dext and releasing when the hardware is removed, and finally some processing code (at the user level) which executes on this shared block of memory from the dext. The shared memory is allocated using an IOBufferMemoryDescriptor: IOBufferMemoryDescriptor::Create(kIOMemoryDirectionNone, sizeof(sharedMemoryBlock), IOVMPageSize, &(ivars->mSharedMemoryBlockMemDesc)); The User Client Library acquires a mapped pointer to this memory by calling IOConnectMapMemory: IOConnectMapMemory(mConnect, kMemoryType_SharedMemoryBlock, mach_task_self(), (mach_vm_address_t*)&mUserClientSharedBlockPtr, (mach_vm_size_t*)&mSizeOfUserClientSharedBlock, kIOMapAnywhere); …which triggers the dext’s IOUserClient subclass' “CopyClientMemoryForType_Impl”. That code adds a retain and returns a pointer to the IOBufferMemoryDescriptor: case kMemoryType_SharedMemoryBlock: // error checks first (make sure it’s allocated and initialized, etc) ivars->mSharedMemoryBlockMemDesc->retain(); *memory = ivars->mSharedMemoryBlockMemDesc; break; IOConnectMapMemory returns the “mapped pointer” (in mUserClientSharedBlockPtr) to the User Client Library, which in turn provides it to the processing code. The processing code checks the pointer validity, and if valid, runs its processing. This worked fine with a kext implementation. This fails with dext implementation, because during the processing call (after validity check but during usage) the mapped pointer can become NULL, which seems to be against the design pattern, and causes the application to crash due to an access violation (dereferencing NULL). I assume I am doing something incorrect here, but I’m not seeing what it is. The memory was retained, so it should not be deleted until the User Client Library has released it, but the only release available would be IOConnectUnmapMemory, and that fails with “invalid argument” (0xE00002C2) after the device is hot-unplugged. I am not finding IOConnectMapMemory examples on developer.apple.com. I have verified via the forums that IOConnectMapMemory is still a recommended practice with DriverKit development: https://developer.apple.com/forums/thread/803947?answerId=862249022#862249022 . What’s the trick here for stability? The device is a peripheral which can be unplugged or turned off at any time, which would result in the dext and user client library code tearing down the structures and memory, but it should be able to do so safely without causing access violations. (Note, this has been simplified for the purpose of focusing the question, in reality there are 4 separate memory blocks which are shared in this fashion: two ring buffers, main engine status, and client status. They each use their own memory_type definition, but a general solution is needed and can be applied to all 4, and there can be multiple clients at any point in time).
Replies
1
Boosts
0
Views
1.1k
Activity
1w
Network UPS?
I found some nice code that implements a NUT client, and now I want to take the next step -- I would like to get it to show up as a UPS for macOS. But I've never done anything with IOKit... and there don't seem to be a lot of examples of, maybe, IOPowerSources?
Replies
6
Boosts
0
Views
464
Activity
1w
Crashe__CFRunLoopServiceMachPort.cold 96% Foreground
Hello, we have encountered a large number of __CFRunLoopServiceMachPort.cold crashes on iOS 26. These crashes frequently occur when the app transitions from the background to the foreground or is launched after sitting idle for a period of time. Despite extensive analysis, we have been unable to find a solution. Currently, the crash data indicates that this issue is specific to iOS 26. We would greatly appreciate your assistance. Thank you very much! Hardware Model: iPhone18,1 OS Version: iPhone OS 26.5.2 (23F84) Release Type: User Baseband Version: 1.60.02 Crash Reporter Key: fda96a4036dcb83e124660e11b654c9484b81dae Incident Identifier: EF18C4DD-7624-42D0-BA72-F17BBC263B16 Time Awake Since Boot: 2900000 seconds Triggered by Thread: 0, Dispatch Queue: com.apple.main-thread Exception Type: EXC_BREAKPOINT (SIGTRAP) Exception Codes: 0x0000000000000001, 0x00000001917d316c Termination Reason: Namespace SIGNAL, Code 5, Trace/BPT trap: 5 Terminating Process: exc handler [82210] Application Specific Information: (ipc/rcv) invalid name Thread 0 name: Dispatch queue: com.apple.main-thread Thread 0 Crashed: 0 CoreFoundation 0x1917d316c __CFRunLoopServiceMachPort.cold.1 + 64 1 CoreFoundation 0x19168a444 __CFRunLoopServiceMachPort + 416 2 CoreFoundation 0x191654310 __CFRunLoopRun + 1188 3 CoreFoundation 0x19165354c _CFRunLoopRunSpecificWithOptions + 532 4 GraphicsServices 0x236df7498 GSEventRunModal + 120 5 UIKitCore 0x19734c244 -[UIApplication _run] + 796 6 UIKitCore 0x1972b7158 UIApplicationMain + 332 7 KMMVideo 0x1047fe24c 0x104304000 + 5218892 8 dyld 0x18e261c1c start + 6928 Thread 1 name: transmit_hls_7683_193735 Thread 1: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 libc++.1.dylib 0x1a0d5dbcc std::__1::condition_variable::wait(std::__1::unique_lockstd::__1::mutex&) + 32 3 iOSPlayer 0x118cd6114 a_task_runner::worker() + 116 4 iOSPlayer 0x118cd5650 a_task_runner::work_thread() + 196 5 iOSPlayer 0x118cd654c void* std::__1::__thread_proxy[abi:ne200100]<std::__1::tuple<std::__1::unique_ptr<std::__1::__thread_struct, std::__1::default_deletestd::__1::__thread_struct>, void (a_task_runner::)(), a_task_runner>>(void*) + 72 6 libsystem_pthread.dylib 0x1f0854438 _pthread_start + 136 7 libsystem_pthread.dylib 0x1f08508cc thread_start + 8 Thread 2: 0 libsystem_kernel.dylib 0x2407d9ed8 read + 8 1 XLTranscodeKit 0x115bb5f4c runtime.read_trampoline.abi0 + 28 Thread 3: Thread 4: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 XLTranscodeKit 0x115bb6648 runtime.pthread_cond_wait_trampoline.abi0 + 24 3 XLTranscodeKit 0x115bb4fb8 runtime.asmcgocall.abi0 + 200 4 ??? 0xd65f03c0 ??? Thread 5: 0 XLTranscodeKit 0x115b3eb68 */bytealg.IndexByteString + 40 1 XLTranscodeKit 0x115b966b8 runtime.findnull + 104 Thread 6: 0 libsystem_kernel.dylib 0x2407db8dc kevent + 8 1 XLTranscodeKit 0x115bb6398 runtime.kevent_trampoline.abi0 + 40 Thread 7: 0 libsystem_kernel.dylib 0x2407da5e8 __psynch_cvwait + 8 1 libsystem_pthread.dylib 0x1f0852b48 _pthread_cond_wait + 980 2 XLTranscodeKit 0x115bb6648 runtime.pthread_cond_wait_trampoline.abi0 + 24 3 XLTranscodeKit 0x115bb4fb8 runtime.asmcgocall.abi0 + 200 4 ??? 0xd65f03c0 ???
Replies
3
Boosts
0
Views
396
Activity
1w
Can an ExtensionFoundation-based extension on macOS have its own extension point and host its own extensions?
It is possible for an extension to an app (based on ExtensionFoundation) to declare its own extension point and host its own ExtensionFoundation extensions? Based on the documentation, I am guessing the answer is no, but worth double-checking. What would be the reason to prevent this? Every ExtensionFoundation extension runs in its own process, and may have need to be extended safely just as its host app does. Thank you!
Replies
3
Boosts
0
Views
224
Activity
1w
Removing stale Local Network entries?
Hello, I'm desperately looking for a way to purge the contents of the Local Network allowlist in System Settings. Every version of a test app I've ever used gets an entry in there, and apparently so does each build of Chrome and Claude Code. Claude recommended I include the following context, and if there's a specific answer to that, great, but any way of purging this list would make me very happy. ==== Caution: slop below this line ==== macOS 27.0 (26A428), Apple silicon. The Local Network list has 471 entries, many dead: Chrome code_sign_clone paths that no longer exist, old ad-hoc builds, uninstalled apps. The pane can't remove any. Is there a supported way to remove entries or reset the list, short of Recovery? Editing /Library/Preferences/com.apple.networkextension.plist as root fails with EPERM, both rename-over and open-for-write. New files in that directory work. SIP is on, the file has no flags or xattrs, Full Disk Access didn't help, and there are no Sandbox/TCC denials in the log. What protects this file?
Replies
3
Boosts
0
Views
461
Activity
1w
Custom Installer Plugin (x86_64 bundle) is not loaded on macOS 26A428 / 25G229 / 24H23, causing an installer GUI pane to be skipped
Summary A third-party PKG installer that ships a custom Installer Plugin no longer displays one of its selection panes. The plugin bundle appears not to be loaded, so the pane that it provides is silently skipped and the user cannot choose the intended installation option. This behavior started with recent macOS releases and did not occur on the immediately preceding versions, so it looks like a regression. Environment Machine: MacBook Pro 14-inch (M3) Affected builds: macOS 27.0 (26A428) macOS 26.7 (25G229) macOS 15.8 (24H23) Not affected: macOS 26.6 and earlier macOS 15.7 and earlier Reproducibility: every time Plugin binary: Mach-O 64-bit bundle, x86_64 only (no arm64 slice) Steps to Reproduce Download the Epson iProjection Ver.4.04 installer from the vendor support site: https://support.epson.net/setupnavi/?LG2=EN&OSC=MI&PINF=vpapp&MKN=EB-770Fi Mount the downloaded disk image and run the PKG installer. Step through the installer GUI and observe the pane transitions. Expected Result The installer GUI shows the "Application type" selection pane provided by the bundled Installer Plugin. Actual Result The "Application type" pane is never shown. The installer proceeds as if the plugin did not exist, and the user cannot select the installation type. What I Checked 1. The plugin is present inside the PKG pkgutil --expand-full PKG_PATH DEST_DIR The expanded payload contains the plugin bundle and its Mach-O executable under Contents/MacOS. 2. Architecture of the plugin binary file DEST_DIR/PluginName.bundle/Contents/MacOS/PluginName Result: Mach-O 64-bit bundle x86_64. It is a single-architecture binary with no arm64 slice. 3. The plugin is actually touched at install time sudo fs_usage -w -f filesys InstallerRemotePluginService-x86 opens the plugin executable inside the installer's temporary directory (a path under /private/tmp/com.apple.installer* ). So the plugin is reached as a load target, but the pane still does not appear. 4. Code signature validation When the installer is launched directly from the mounted disk image, code signature validation fails with: Too many levels of symbolic links My working theory is that the bundle contents are turned into symbolic links when the plugin is expanded, and that this causes codesign validation to fail, so the plugin is rejected before it can register its pane. 5. Code evaluation by syspolicyd log stream --info --debug --predicate 'process == "syspolicyd"' GK package assessment, GK process assessment and GK performScan entries are present, so Gatekeeper evaluation itself is running. The following also appears: Error Domain=NSOSStatusErrorDomain Code=-67062 Unsigned code in: PST: (path: REDACTED), (team: (null)), (id: (null)), (bundle_id: (null)) The PST path is anonymized in the log, so I could not confirm that this particular assessment refers to the plugin bundle. 6. XProtect evaluation results differ between versions log stream --info --debug --predicate 'process == "syspolicyd"' On the versions where the installer works correctly, the GK Xprotect results lines explicitly include a file URL pointing at the plugin bundle inside the installer temporary directory. On the affected builds, searching the same log for the plugin bundle name returns zero matches. That suggests the bundle is not being processed as an XProtect evaluation target at all on the newer builds. Question Was there a change in how Installer Plugins are expanded or validated in these releases, in particular around symlinked bundle contents or single-architecture x86_64 plugins? Any guidance on the supported way to ship an Installer Plugin so that it is still loaded on current macOS would be appreciated.
Replies
1
Boosts
0
Views
267
Activity
1w
Error Domain=PKPassKitErrorDomain Code=2
We are getting this error frequently and our customers are getting increasing frustrated when they are unable to add their credit card to Apple Wallet. There is no clear explanation on when this error arises. I sincerely request help to understand the cause of this issue. Device info: Apple iOS 26.6.1.
Replies
0
Boosts
0
Views
94
Activity
1w
In App Provisioning PKErrorHTTPResponseStatusCodeKey=500
Hello, we are developing in app provisioning of our American Express network cards. After clicking add to apple wallet in our app, I launch the PKAddPaymentPassViewController and click next. It loads for a few seconds and then I get: [<private>] ProvisioningOperationComposer: Step '<private>' failed with error Error Domain=PKProvisioningErrorDomain Code=5 UserInfo={PKErrorHTTPResponseStatusCodeKey=500} Does anyone have any insight on what this error means?
Replies
5
Boosts
1
Views
1.4k
Activity
1w
Family Controls authorization error
Hi everyone, I'm developing an iOS app that uses Apple's Family Controls / Screen Time APIs. I've encountered a strange issue when testing with multiple devices: The app works normally on the first device. When I install the same TestFlight build on a second device, the user completes the Family Controls authorization successfully. Immediately after authorization, an error appears: "Family Controls is only available for one application." After dismissing the error, the app still works normally. Screen Time / Shield functionality also appears to work as expected. The issue seems to occur specifically when authorizing the app on a second device. Has anyone encountered this error before?
Replies
0
Boosts
0
Views
75
Activity
1w
StoreKit External Purchases or Offers entitlement missing from macOS provisioning profile
Hey We are implementing EU external purchases for both our iOS and native macOS apps as it's written here: https://developer.apple.com/br/support/payment-options-on-the-app-store-in-the-eu For our App ID, we enabled StoreKit External Purchases or Offers, whose entitlement key is: com.apple.developer.storekit.custom-purchase-link.allowed-regions The capability works for iOS, but newly generated macOS provisioning profiles do not contain this entitlement. In Certificates, Identifiers & Profiles, the capability itself shows Platform Support: iOS, tvOS, watchOS, visionOS - macOS is not listed. However, the StoreKit documentation for ExternalPurchaseCustomLink and the EU alternative-payment documentation appear to describe external-purchase support more generally. Could you please clarify: Is com.apple.developer.storekit.custom-purchase-link.allowed-regions currently supported for native macOS apps distributed through the Mac App Store? If not, what entitlement and API should a native macOS app use for EU external purchases and external-purchase token reporting? Is macOS support for the StoreKit External Purchases or Offers entitlement planned or available through a separate entitlement request? At the moment, our macOS provisioning profiles cannot contain this entitlement because macOS is not listed as a supported platform for this capability. Thank you!
Replies
0
Boosts
0
Views
525
Activity
1w
[macOS 27] Non-sandboxed Developer ID app blocked from accessing Chrome and Firefox directories under ~/Library/Application Support/ — intentional TCC change?
Environment: App: Developer ID signed, non-sandboxed macOS app Browsers affected: Google Chrome, Mozilla Firefox Safari: Working fine on macOS 27 Working on: macOS 26 and earlier Broken on: macOS 27 (Golden Gate) Issue Our non-sandboxed, Developer ID signed macOS app interacts with Chrome and Firefox directories under ~/Library/Application Support/ as part of its browser extension deployment workflow. On macOS 26 and earlier, this worked without any special permissions. On macOS 27, the same operations are silently blocked — no TCC prompt is shown to the user, access is simply denied. Granting Full Disk Access to our app via System Settings > Privacy & Security > Full Disk Access resolves the issue completely on macOS 27. Safari is unaffected — our Safari extension is bundled directly inside our app and continues to work correctly on macOS 27 without any additional permissions. Question Has macOS 27 intentionally introduced TCC or MACL-based protection over Chrome and Firefox directories under ~/Library/Application Support/, blocking access from non-owner processes including non-sandboxed Developer ID apps? If this is an intentional change, is Full Disk Access the expected requirement going forward, or is there a more targeted entitlement or Apple-recommended approach for a non-sandboxed app that legitimately needs to access browser directories as part of an extension deployment workflow?
Replies
1
Boosts
0
Views
240
Activity
1w