Skip to content

Stop sending the Xcode client identifier Apple now refuses - #194

Merged
parawanderer merged 1 commit into
mainfrom
fix/apple-drops-the-xcode-client
Sep 13, 2026
Merged

parawanderer merged 1 commit into
mainfrom
fix/apple-drops-the-xcode-client

Conversation

@parawanderer

@parawanderer parawanderer commented Sep 13, 2026 •

Copy link
Copy Markdown
Owner

Fixes #168, #176, #181.

Apple's edge refuses any POST to gsa.apple.com/grandslam/GsService2 whose X-MMe-Client-Info names com.apple.dt.Xcode, before any credential is examined — it returns a 190-byte HTML page from Server: Apple rather than a GSA plist, which arrives as HTTP 503 and reads like an outage. Naming com.apple.akd, the daemon that actually performs this call on macOS, is answered normally.

Fixed in the fork at b6f544b and repinned here in all four places rule 14 lists.

Verification

End to end against a real Apple ID: a sign-in that had failed for days now completes.

With the library's own request shape and real Anisette data, one variable changed:

X-MMe-Client-Info app token Result
com.apple.dt.Xcode/3594.4.19 HTTP 503, 190-byte edge page
com.apple.akd/1.0 HTTP 200, a real GSA plist

And without any account:

curl -so /dev/null -w '%{http_code}\n' -X POST --data-binary t \
  -H 'X-MMe-Client-Info: <Mac14,2> <macOS;15.7.5;24G624> <com.apple.AuthKit/1 (com.apple.dt.Xcode/3594.4.19)>' \
  https://gsa.apple.com/grandslam/GsService2      # 503

  ... (com.apple.akd/1.0)> ...                    # 401 — it arrived

Credit

Not our diagnosis. AltStore found and isolated it in altstoreio/AltStore#1790, shipped in AltServer 1.7.6. The same block took out SideStore, Macless Haystack, OpenBubbles and every Anisette server. Offered upstream as malmeloo/FindMy.py#271; Dadoum/anisette-v3-server#60 is the same one-token change.

With thanks to community contributors that also investigated and found this issue: @LiamJ74, in parawanderer/FindMy.py#2.

Corrections

Four files said the shared constant serial was the leading suspect for these 503s. It was not, and each of them now says so rather than leaving the correction only in the rule. Serials were eliminated on the way to the real cause — a drawn one, the old constant, and upstream's bare 0 were all refused identically, and a QEMU macOS VM signs in with a fabricated C02… serial that is not even unique across installs. The per-install serial from #182 stays on its own merits and explains none of the 503s.

Rule 18 records the two things that cost an afternoon:

  • The answer was already published by a neighbouring project two days earlier. This project shares its auth path with AltStore, SideStore, Macless Haystack and OpenBubbles, so when something that worked yesterday breaks for everyone, reading those trackers beats bisecting this one.
  • The Xcode identifier was tested and wrongly cleared early, because the patch went to the Anisette header builder while _gsa_request composes that header at a separate call site. The patched value never reached the wire, and the false negative sent the investigation elsewhere for hours.

Interactively co-authored by Claude Code and @parawanderer

Every sign-in has been failing with HTTP 503 from Grand Slam since late August. Apple's edge
refuses any POST to `gsa.apple.com/grandslam/GsService2` whose `X-MMe-Client-Info` names
`com.apple.dt.Xcode`, before a credential is examined - a 190-byte HTML page from `Server: Apple`
instead of a GSA plist. Naming `com.apple.akd`, the daemon that really makes this call on macOS,
is answered normally.

Fixed in the fork at `b6f544b` and repinned here, in all four places rule 14 lists. Verified end
to end against a real Apple ID: a sign-in that had failed for days now completes, and the
library's own request shape returns HTTP 200 with akd against 503 with Xcode, one variable
changed.

**Not our diagnosis.** AltStore found it (altstoreio/AltStore#1790, shipped in AltServer 1.7.6);
the same block took out SideStore, Macless Haystack, OpenBubbles and every Anisette server.
Upstream fix offered as malmeloo/FindMy.py#271, and Dadoum/anisette-v3-server#60 is the same
one-token change.

Four files claimed the shared constant serial was the leading suspect for #168, #176 and #181.
It was not, and the correction is in each of them rather than only in the rule: serials were
eliminated on the way to the real cause - a drawn one, the old constant, and upstream's bare `0`
all refused identically - and a QEMU macOS VM signs in with a fabricated `C02...` serial that is
not unique across installs. The per-install serial stays on its own merits; it explains none of
the 503s.

Rule 18 records the two things that cost the afternoon: the answer was already published by a
neighbouring project two days earlier, and the Xcode identifier was tested and wrongly cleared
early because the patch went to the Anisette header builder while `_gsa_request` composes that
header at a separate call site.
@parawanderer
parawanderer merged commit 5a83d16 into main Sep 13, 2026
8 checks passed

This branch was successfully deployed

1 active deployment
Android Build — 345ce66f Deployed Sep 13, 2026 by parawanderer via Instrumented tests (emulator) #242
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Exporter: 1.4.0

1 participant