Stop sending the Xcode client identifier Apple now refuses - #194
Merged
Merged
Conversation
Every sign-in has been failing with HTTP 503 from Grand Slam since late August. Apple's edge refuses any POST to `gsa.apple.com/grandslam/GsService2` whose `X-MMe-Client-Info` names `com.apple.dt.Xcode`, before a credential is examined - a 190-byte HTML page from `Server: Apple` instead of a GSA plist. Naming `com.apple.akd`, the daemon that really makes this call on macOS, is answered normally. Fixed in the fork at `b6f544b` and repinned here, in all four places rule 14 lists. Verified end to end against a real Apple ID: a sign-in that had failed for days now completes, and the library's own request shape returns HTTP 200 with akd against 503 with Xcode, one variable changed. **Not our diagnosis.** AltStore found it (altstoreio/AltStore#1790, shipped in AltServer 1.7.6); the same block took out SideStore, Macless Haystack, OpenBubbles and every Anisette server. Upstream fix offered as malmeloo/FindMy.py#271, and Dadoum/anisette-v3-server#60 is the same one-token change. Four files claimed the shared constant serial was the leading suspect for #168, #176 and #181. It was not, and the correction is in each of them rather than only in the rule: serials were eliminated on the way to the real cause - a drawn one, the old constant, and upstream's bare `0` all refused identically - and a QEMU macOS VM signs in with a fabricated `C02...` serial that is not unique across installs. The per-install serial stays on its own merits; it explains none of the 503s. Rule 18 records the two things that cost the afternoon: the answer was already published by a neighbouring project two days earlier, and the Xcode identifier was tested and wrongly cleared early because the patch went to the Anisette header builder while `_gsa_request` composes that header at a separate call site.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #168, #176, #181.
Apple's edge refuses any POST to
gsa.apple.com/grandslam/GsService2whoseX-MMe-Client-Infonamescom.apple.dt.Xcode, before any credential is examined — it returns a 190-byte HTML page fromServer: Applerather than a GSA plist, which arrives as HTTP 503 and reads like an outage. Namingcom.apple.akd, the daemon that actually performs this call on macOS, is answered normally.Fixed in the fork at
b6f544band repinned here in all four places rule 14 lists.Verification
End to end against a real Apple ID: a sign-in that had failed for days now completes.
With the library's own request shape and real Anisette data, one variable changed:
X-MMe-Client-Infoapp tokencom.apple.dt.Xcode/3594.4.19com.apple.akd/1.0And without any account:
Credit
Not our diagnosis. AltStore found and isolated it in altstoreio/AltStore#1790, shipped in AltServer 1.7.6. The same block took out SideStore, Macless Haystack, OpenBubbles and every Anisette server. Offered upstream as malmeloo/FindMy.py#271; Dadoum/anisette-v3-server#60 is the same one-token change.
With thanks to community contributors that also investigated and found this issue: @LiamJ74, in parawanderer/FindMy.py#2.
Corrections
Four files said the shared constant serial was the leading suspect for these 503s. It was not, and each of them now says so rather than leaving the correction only in the rule. Serials were eliminated on the way to the real cause — a drawn one, the old constant, and upstream's bare
0were all refused identically, and a QEMU macOS VM signs in with a fabricatedC02…serial that is not even unique across installs. The per-install serial from #182 stays on its own merits and explains none of the 503s.Rule 18 records the two things that cost an afternoon:
_gsa_requestcomposes that header at a separate call site. The patched value never reached the wire, and the false negative sent the investigation elsewhere for hours.