3 ms·
iOS bans loading external executable code. > 2.5.2 Apps should be self-contained in their bundles, and may not read or write data outside the designated contai
by gnomewascool 8y ago
iOS bans loading external executable code.
> 2.5.2 Apps should be self-contained in their bundles, and may not read or write data outside the designated container area, nor may they download, install, or execute code which introduces or changes features or functionality of the app, including other apps. Educational apps designed to teach, develop, or allow students to test executable code may, in limited circumstances, download code provided that such code is not used for other purposes. Such apps must make the source code provided by the Application completely viewable and editable by the user.
https://developer.apple.com/app-store/review/guidelines/#software-requirements https://developer.apple.com/app-store/review/guidelines/#sof...
(Edit: obviously the ban is via reviewing apps in the store, not on the software level.)
- pilif 8y ago> obviously the ban is via reviewing apps in the store, not on the software level it's also on the software level. If you are an app and want to mark parts of your memory as executable, you need a special entitlement that requires a signature from Apple. Only a very small amount of OS-bundled apps (Safari for example) and no third-party app have this entitlement. This is a reason why for a long time web-views embedded into apps couldn't make use of JIT compiled JavaScript: Because the web view was loaded in-process with your app, there was no way to execute any of the compiled code. Only with WKWebView this was fixed by running the webview in a secondary process that has the necessary entitlements and then rendering the view inside of your process. Getting there took Apple quite some time though. Only static code loaded from disk is marked executable, but that's not writable in memory and it's only loaded into memory when it has a valid code signature signed by Apple. So unless you manage to get Apple to sign your dynamically loaded payload, even if you sneak the functionality past app-review, there's no way to execute it.