The 503s were never ours, and four files said otherwise - #192
Closed
parawanderer wants to merge 1 commit into
Closed
parawanderer wants to merge 1 commit into
parawanderer wants to merge 1 commit into
Conversation
`AGENTS.md` rule 11, both `identity.py` docstrings and `AdiDeviceIdentity.LEGACY_SERIAL` all named the shared constant serial as the leading suspect for #168, #176 and #181, and described drawing a serial per install as the cheap way to confirm it. That was written before anybody tested it. It was tested on 2026-09-13, against an account Apple was actively refusing, and eliminated in stages. Every one of these was refused with 503: | Varied | Result | | --- | --- | | A freshly drawn serial instead of the shared constant | 503 | | Fresh `uid` and `devid` | 503 | | Fresh ADI provisioning | 503 | | Three network locations, including the account's own country | 503 | | A second, unrelated Apple ID | 503 | | A second machine, different OS | 503 | | **Unmodified upstream FindMy.py**, which has no serial parameter and sends `0` | 503 | It is an Apple-side change hitting the whole class of client, and three independent implementations reported it within days of each other: `malmeloo/FindMy.py#268` ("Something changed on Apple's side, not sure what yet"), a Macless Haystack report on `seemoo-lab/openhaystack#63`, and `OpenBubbles/openbubbles-app#267`. Our own reports run from 2026-08-29, ahead of upstream's, which fits a gradual rollout rather than a different cause. The per-install serial is kept. One serial arriving from thousands of installs against thousands of machine identities is a shape no real hardware produces, and that argument never depended on the 503s. What is removed is the claim that it fixes them, and every file now says so explicitly so the hypothesis is not re-derived from the paragraph above it. What this project can actually do about it is rule 15 and `ICloudFailures`: say plainly that Apple declined, and stop sending people to the bug tracker over it. That shipped in #177.
Owner
Author
|
Superseded by #194. This branch corrected the serial claim but replaced it with a different wrong conclusion — that the 503s were an unfixable Apple-side change. They were Apple refusing the
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Four places —
AGENTS.mdrule 11, bothidentity.pydocstrings, andAdiDeviceIdentity.LEGACY_SERIAL— named the shared constant serial as the leading suspect for #168, #176 and #181, and called the per-install serial the cheap way to confirm it. All of that was written before anyone tested it.It was tested today against an account Apple was actively refusing, and eliminated in stages. Each of these was refused with 503:
uidanddevidX-Apple-I-SRL-NO: 0Three independent implementations reported it within days:
Our reports start 2026-08-29, ahead of upstream's, which fits a gradual rollout rather than a separate cause.
The per-install serial stays. One serial arriving from thousands of installs against thousands of machine identities is a shape no real hardware produces, and that argument never rested on the 503s. What goes is the claim that it fixes them — stated explicitly in each file, so the next reader does not re-derive the hypothesis from the paragraph above it.
What this project can actually do is rule 15: say plainly that Apple declined and stop sending people to the bug tracker. That shipped in #177.