Browserenginekit

作者 dpearson26998d90fd121a26無授權條款1.1K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫2 個月前更新

Build alternative browser engines using BrowserEngineKit. Use when developing a non-WebKit browser engine for iOS/iPadOS in supported regions, managing web content/rendering/networking extension processes, configuring GPU and networking process capabilities, checking alternative-engine device eligibility, or reviewing BrowserEngineKit entitlements and Info.plist setup.

AI 產生的概覽

指導在 iOS/iPadOS 上使用 BrowserEngineKit 建構非 WebKit 的替代瀏覽器引擎,涵蓋權限、程序與 XPC。

功能
此技能為在 iOS 與 iPadOS 上使用 Apple 的 BrowserEngineKit 框架開發替代瀏覽器引擎提供參考指引。內容涵蓋資格檢查、所需權限、宿主應用程式與網頁內容、網路及算繪擴充功能的架構、XPC 啟動程序與程序管理、能力授予、圖層託管、文字互動、沙箱、JIT 以及下載監控。它也列出常見錯誤與審查清單,並在配套參考檔案中提供延伸模式。
適用情境
適用於為 iOS/iPadOS 開發或審查非 WebKit 瀏覽器引擎、設定擴充功能程序與權限,或檢查裝置是否具備替代引擎資格的情況。在發佈前審查 BrowserEngineKit 權限與 Info.plist 設定時同樣適用。
執行需求
不含指令碼,僅為說明文件與參考檔案。開發以 Swift 與目前的 Apple SDK 為目標,需使用 Xcode,並依賴 Apple 核准的權限設定檔、受支援地區的裝置資格,以及 BrowserEngineKit、BrowserKit 與 BrowserEngineCore 框架。

BrowserEngineKit

Framework for building web browsers with alternative (non-WebKit) rendering engines on iOS and iPadOS. Provides process isolation, XPC communication, capability management, and system integration for browser apps that implement their own HTML/CSS/JavaScript engine. Examples target Swift 6.3 and current Apple SDKs.

BrowserEngineKit is a specialized framework. Alternative browser engines are available only through Apple-approved entitlement profiles and supported-region device eligibility. EU support applies to eligible users on iOS 17.4+ and iPadOS 18+; Japan support starts with iOS 26.2 and adds explicit PAC/MIE security requirements for browser apps. Development and testing can occur anywhere. The companion frameworks BrowserEngineCore (low-level primitives) and BrowserKit (eligibility checks, data transfer) support the overall workflow.

Contents

Overview and Eligibility

Eligibility Checking

Use BEAvailability from the BrowserKit framework to check whether the device is eligible for alternative browser engines. BEAvailability is available on iOS/iPadOS 18.4+:

swift
import BrowserKit
do {    let eligible = try await BEAvailability.isEligible(for: .webBrowser)    guard eligible else { return /* fall back or explain */ }    // Device supports alternative browser engines} catch {    // Handle eligibility lookup failure}

Eligibility depends on the device region and OS version. Do not hard-code region checks; rely on the system API.

Availability anchors: process APIs are iOS/iPadOS 17.4+, BEDownloadMonitor is iOS 18.2+, .revision2 restricted sandbox is iOS 26+, and RenderingExtensionFeature.coreML is iOS 26.2+.

Entitlements

Browser App (Host)

The host app requires two entitlements:

EntitlementPurpose
com.apple.developer.web-browserEnables default-browser candidacy
com.apple.developer.web-browser-engine.hostEnables alternative engine extensions

Both must be requested from Apple. The request process varies by region.

Extension Entitlements

Each extension target requires its type-specific entitlement set to true:

Extension TypeEntitlement
Web contentcom.apple.developer.web-browser-engine.webcontent
Networkingcom.apple.developer.web-browser-engine.networking
Renderingcom.apple.developer.web-browser-engine.rendering

Optional Entitlements

EntitlementExtensionPurpose
com.apple.security.cs.allow-jitWeb contentJIT compilation of scripts
com.apple.developer.kernel.extended-virtual-addressingWeb contentRequired alongside JIT
com.apple.developer.memory.transfer_sendRenderingSend memory attribution; value is host app bundle ID
com.apple.developer.memory.transfer_acceptWeb contentAccept memory attribution; value is host app bundle ID
com.apple.developer.web-browser-engine.restrict.notifydWeb contentRestrict notification daemon access

Embedded Browser Engine (Non-Browser Apps)

Apps that are not browsers but embed an alternative engine for in-app browsing use different entitlements:

EntitlementPurpose
com.apple.developer.embedded-web-browser-engineEnable embedded engine
com.apple.developer.embedded-web-browser-engine.engine-associationDeclare engine ownership

engine-association is available starting iOS/iPadOS/Mac Catalyst 26.2 and is set to first-party when you own the engine or third-party when another developer owns it. Embedded engines use arm64 only (not arm64e), cannot include browser extensions, and cannot use JIT compilation.

Japan-Specific Requirements

Browser apps distributed in Japan are supported on iOS 26.2+ and must adopt the current security mitigations Apple lists for Japan, including Pointer Authentication Codes and Memory Integrity Enforcement for relevant allocators and extension processes. Enable hardware memory tagging with com.apple.security.hardened-process.checked-allocations; Apple strongly recommends enabling it in the EU as well.

Architecture

A browser built with BrowserEngineKit consists of four components running in separate processes:

Host App (UI, coordination)  |  |-- XPC --> Web Content Extension (HTML parsing, JS, DOM)  |-- XPC --> Networking Extension (URLSession, sockets)  |-- XPC --> Rendering Extension (Metal, GPU, media)

The host app launches and manages all extensions. Extensions cannot launch other extensions. Extensions communicate with each other through anonymous XPC endpoints brokered by the host app.

Bootstrap Sequence

  1. Host launches web content, networking, and rendering extensions
  2. Host creates XPC connections to each extension
  3. Host requests anonymous XPC endpoints from networking and rendering
  4. Host sends both endpoints to the web content extension via a bootstrap message
  5. Web content extension connects directly to networking and rendering

This architecture follows the principle of least privilege: the web content extension works with untrusted data but has no direct OS resource access.

Process Management

Launching Extensions

Each extension type has a corresponding process class in the host app:

swift
import BrowserEngineKit
// Web content (one per tab or iframe)let contentProcess = try await WebContentProcess(    bundleIdentifier: nil,    onInterruption: {        // Handle crash or OS interruption    })
// Networking (typically one instance)let networkProcess = try await NetworkingProcess(    bundleIdentifier: nil,    onInterruption: {        // Handle interruption    })
// Rendering / GPU (typically one instance)let renderingProcess = try await RenderingProcess(    bundleIdentifier: nil,    onInterruption: {        // Handle interruption    })

Pass nil for bundleIdentifier to use the default extension target. The interruption handler fires if the extension crashes or is terminated by the OS.

Creating XPC Connections

swift
let connection = try contentProcess.makeLibXPCConnection()// Use connection for inter-process messaging

Each process type provides makeLibXPCConnection() to create an xpc_connection_t for communication.

Stopping Extensions

swift
contentProcess.invalidate()

After calling invalidate(), no further method calls on the process object are valid.

Extension Types

Web Content Extension

Hosts the browser engine's HTML parser, CSS engine, JavaScript interpreter, and DOM. Conform to WebContentExtension to handle incoming XPC connections:

swift
import BrowserEngineKit
@mainstruct MyWebContentExtension: WebContentExtension {    func handle(xpcConnection: xpc_connection_t) {        // Set up message handlers on the connection    }}

Configure via WebContentExtensionConfiguration in the extension's EXAppExtensionAttributes.

Networking Extension

Handles all network requests using URLSession or socket APIs. One instance serves all tabs:

swift
import BrowserEngineKit
@mainstruct MyNetworkingExtension: NetworkingExtension {    func handle(xpcConnection: xpc_connection_t) {        // Handle network request messages    }}

Configure via NetworkingExtensionConfiguration.

Rendering Extension

Accesses the GPU via Metal for video decoding, compositing, and complex rendering. One instance typically serves the entire browser:

swift
import BrowserEngineKit
@mainstruct MyRenderingExtension: RenderingExtension {    init() {        if #available(iOS 26.2, macOS 26.2, *) {            enableFeature(.coreML)        }    }
    func handle(xpcConnection: xpc_connection_t) {        // Handle rendering commands    }}

Configure via RenderingExtensionConfiguration.

Capabilities

Grant capabilities to extensions so the OS schedules them appropriately:

swift
// Grant foreground priority to an extensionlet grant = try contentProcess.grantCapability(.foreground)
// ... extension does foreground work ...
// Relinquish when donegrant.invalidate()

Available Capabilities

CapabilityUse Case
.foregroundActive tab rendering, visible content
.backgroundBackground tasks, prefetching
.suspendedMinimal activity, pending cleanup
.mediaPlaybackAndCapture(environment:)Audio/video playback, camera/mic capture

Media Environment

For media capabilities, create a MediaEnvironment tied to a page URL. The environment supports AVCaptureSession for camera/mic access and is XPC-serializable for cross-process transport:

swift
let mediaEnv = MediaEnvironment(webPage: pageURL)let grant = try contentProcess.grantCapability(    .mediaPlaybackAndCapture(environment: mediaEnv))try mediaEnv.activate()let captureSession = try mediaEnv.makeCaptureSession()

Visibility Propagation

Attach a visibility propagation interaction to browser views so extensions know when content is on screen. Both WebContentProcess and RenderingProcess provide createVisibilityPropagationInteraction().

Layer Hosting and View Coordination

The rendering extension draws into a LayerHierarchy, whose content the host app displays via LayerHierarchyHostingView. Handles are passed over XPC. Use LayerHierarchyHostingTransactionCoordinator to synchronize layer updates atomically across processes.

See references/browserenginekit-patterns.md [blocked] for detailed layer hosting examples and transaction coordination.

Text Interaction

Adopt BETextInput on custom text views to integrate with UIKit's text system. This enables standard text selection, autocorrect, dictation, and keyboard interactions.

Key integration points:

  • asyncInputDelegate for communicating text changes to the system
  • handleKeyEntry(_:completionHandler:) for keyboard events
  • BETextInteraction for selection gestures, edit menus, and context menus
  • BEScrollView and BEScrollViewDelegate for custom scroll handling

See references/browserenginekit-patterns.md [blocked] for detailed text interaction implementation.

Sandbox and Security

Restricted Sandbox

After initialization, lock down content extensions using the restricted sandbox:

swift
// In the web content extension, after setup:if #available(iOS 26.0, macOS 26.0, *) {    applyRestrictedSandbox(revision: .revision2)} else {    applyRestrictedSandbox(revision: .revision1)}

This removes access to resources the extension used during startup but no longer needs. Use the latest available revision for the strongest restrictions.

JIT Compilation

Web content extensions that JIT-compile JavaScript must transition pages with BrowserEngineKit's witnessed APIs:

swift
import BrowserEngineCore
be_memory_inline_jit_restrict_rwx_to_rw_with_witness(...)// write generated codebe_memory_inline_jit_restrict_rwx_to_rx_with_witness(...)

Requires the com.apple.security.cs.allow-jit and com.apple.developer.kernel.extended-virtual-addressing entitlements on the web content extension only. If an implementation instead uses pthread_jit_write_with_callback_np, it also needs the JIT write allowlist entitlement; do not present BE_JIT_WRITE_PROTECT_TAG alone as a complete protection strategy.

arm64e Requirement

Distribution builds must satisfy the current alternative-browser entitlement profile's device architecture, PAC, and MIE requirements. Keep the host and extension configuration consistent, include the required device slices, and test the signed archive on eligible devices. Embedded engines differ: they are arm64-only and cannot use JIT. Do not force arm64e onto Simulator builds or copy a one-line ARCHS override that drops required slices.

Downloads

Report download progress to the system using BEDownloadMonitor. Create an access token, initialize the monitor with source/destination URLs and a Progress object, then call beginMonitoring() to show the system download UI. Use resumeMonitoring(placeholderURL:) to resume interrupted downloads. BEDownloadMonitor is available on iOS 18.2+.

See references/browserenginekit-patterns.md [blocked] for full download management examples.

Common Mistakes

DON'T: Skip the bootstrap sequence

swift
// WRONG - content extension has no path to other extensionslet contentProcess = try await WebContentProcess(    bundleIdentifier: nil, onInterruption: {})// Immediately start sending work without connecting to networking/rendering
// CORRECT - broker connections through the host applet networkEndpoint = try await networkProxy.getEndpoint()let renderEndpoint = try await renderProxy.getEndpoint()try await contentProxy.bootstrap(    renderingExtension: renderEndpoint,    networkExtension: networkEndpoint)

DON'T: Launch extensions from other extensions

swift
// WRONG - extensions cannot launch other extensions// (inside a WebContentExtension)let network = try await NetworkingProcess(...)
// CORRECT - only the host app launches extensions// Host app creates all processes, then brokers connections

DON'T: Use extension process objects after invalidation

swift
// WRONGcontentProcess.invalidate()let conn = try contentProcess.makeLibXPCConnection()  // Error
// CORRECT - create a new process if neededlet newProcess = try await WebContentProcess(    bundleIdentifier: nil, onInterruption: {})

DON'T: Apply JIT entitlements to non-content extensions

JIT compilation entitlements (com.apple.security.cs.allow-jit) are valid only on web content extensions. Adding them to the host app, rendering extension, or networking extension causes App Store rejection.

DON'T: Hard-code region eligibility

swift
// WRONGif Locale.current.region?.identifier == "DE" {    useAlternativeEngine()}
// CORRECT - use the system eligibility APIlet eligible = try await BEAvailability.isEligible(for: .webBrowser)if eligible {    useAlternativeEngine()}

DON'T: Forget to set UIRequiredDeviceCapabilities

Without web-browser-engine in UIRequiredDeviceCapabilities, users on unsupported devices can download the app and hit runtime failures.

Review Checklist

  • com.apple.developer.web-browser-engine.host entitlement on host app
  • Each extension has its type-specific entitlement
  • UIRequiredDeviceCapabilities includes web-browser-engine
  • arm64e instruction set configured for all iOS device targets
  • arm64e is not set for Simulator targets
  • Swift packages built with iOSPackagesShouldBuildARM64e workspace setting
  • Extension point identifiers set correctly in each extension's Info.plist
  • Interruption handlers implemented for all process types
  • Bootstrap sequence connects content extension to networking and rendering
  • Capabilities granted before work begins and invalidated when done
  • Visibility propagation interaction added to browser content views
  • Restricted sandbox applied to content extensions after initialization
  • BEAvailability used for eligibility checks instead of manual region logic
  • Memory attribution entitlements use the host app bundle ID as their value
  • Download progress reported via BEDownloadMonitor for active downloads on iOS 18.2+
  • Memory tagging enabled for Japan distribution on iOS 26.2+ (recommended for EU)

References

來源與署名

來源:dpearson2699/swift-ios-skills位於skills/browserenginekit提交8d90fd1

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 dpearson2699/swift-ios-skills 的技能

Widgetkit

dpearson2699

指導實作、審查與改進 iOS、iPadOS、watchOS 與 CarPlay 上的 WidgetKit 小工具與控制項。

Software Development1.1K2 個月前更新

Weatherkit

dpearson2699

指導 iOS 開發者使用 WeatherService 取得 WeatherKit 預報、警報與署名資訊。

Software Development1.1K2 個月前更新

Vision Framework

dpearson2699

Implement computer vision features including text recognition (OCR), face detection, barcode scanning, image segmentation, object tracking, and document scanning in iOS apps. Covers both the modern Swift-native Vision API (iOS 18+) and legacy VNRequest patterns, VisionKit DataScannerViewController for live camera scanning, and CoreMLRequest/VNCoreMLRequest for custom model inference. Use when adding OCR, barcode scanning, face detection, or custom Core ML model inference with Vision.

待分類1.1K2 個月前更新

Tipkit

dpearson2699

Implement and review Apple TipKit feature-discovery UI for iOS 17+ apps. Use when adding or auditing in-app tips, contextual help, coach marks, Tip, TipView, popoverTip, rules, events, actions, display frequency, testing overrides, reusable tip identifiers, or iOS 18+ TipGroup and CloudKit tip sync; avoid for generic SwiftUI navigation or layout outside tip presentation.

待分類1.1K2 個月前更新

Tabletopkit

dpearson2699

指導使用 TabletopKit 在 visionOS 上打造多人空間桌遊,涵蓋棋具、座位、動作與 RealityKit 算繪。

Software Development1.1K2 個月前更新

Swiftui Webkit

dpearson2699

指導在 iOS 26 及更新版本的 SwiftUI App 中使用 WebKit for SwiftUI 嵌入與控制網頁內容。

Software Development1.1K2 個月前更新