From cd36a7a81263c4de6e15accca9101c0d125fcc85 Mon Sep 17 00:00:00 2001 From: m96-chan Date: Thu, 17 Sep 2026 13:40:15 +0900 Subject: [PATCH] docs: add App Review response for issue 48 --- docs/APP_STORE.jp.md | 70 ++++++++++++++++++++--- docs/APP_STORE.md | 133 +++++++++++++++++++++++++++++++++++++------ 2 files changed, 179 insertions(+), 24 deletions(-) diff --git a/docs/APP_STORE.jp.md b/docs/APP_STORE.jp.md index d79930f..e1c7b84 100644 --- a/docs/APP_STORE.jp.md +++ b/docs/APP_STORE.jp.md @@ -2,7 +2,7 @@ [English](APP_STORE.md) | 日本語 -実装済みの機能に基づく原稿です。ビルドはApp Store Connectへアップロード済みですが、審査には未提出です。個人のApple Developer契約とBundle ID `io.github.m96-chan.iossh` で公開を準備します。 +実装済みの機能に基づく原稿です。初回提出は2026年9月16日にGuideline 2.1の追加情報要求で差し戻されました。Appleからバイナリの不具合は指摘されていません。個人のApple Developer契約とBundle ID `io.github.m96-chan.iossh` で公開を準備します。 旧 `moe.technologies.iossh` の開発ビルドとは別アプリとしてインストールされます。保存済みホスト、資格情報、設定、追加フォントは自動移行されません。端末一覧を取得する前に、新アプリから書き出した **Import Tailscale Hosts** で旧ショートカットを置き換えてください。[移行手順](../shortcuts/README.md#updating-from-the-previous-app-identifier)も参照してください。 @@ -34,13 +34,69 @@ iOSSH専用のアカウントやサブスクリプションへのログインは Tailscaleは任意の機能です。通常のSSHはTailscaleなしで確認できます。端末の取り込みは **Import from Tailscale → Set Up Shortcut** から **Import Tailscale Hosts** を追加し、**Fetch Devices** を実行して登録する端末を選びます。 -## 公開までに必要な情報・確認 +## Guideline 2.1への回答 -- ストア名の空き状況、主言語、価格、配信国を確定する。 -- 公開済みの[プライバシーポリシー](PRIVACY.jp.md)と[サポートページ](SUPPORT.jp.md)のURLをApp Store Connectへ登録し、アプリ内の **About** にある同じリンクを確認する。 -- 配布する実装に基づき、App Privacy、年齢区分、暗号化・輸出コンプライアンスの回答を確定する。SSHは依存ライブラリを通じて暗号処理を使うため、`ITSAppUsesNonExemptEncryption` を推測で自動設定していない。 +Submission ID `9afe9cac-389d-4f2d-bb18-7f378de6ccf3`について、以下の情報が要求されました。完成した回答をApp Store Connectの審査メッセージと **App Review Information → Notes** の両方へ貼り付けます。角括弧の値はすべて置き換え、審査用サーバーの認証情報と録画はこのリポジトリへ保存しません。 + +### 回答案(日本語確認用) + +1. **実機の画面録画** + +実機のiPhoneまたはiPadで、アプリ起動 → 審査用SSHホストの追加 → 提供した認証情報で接続 → 実際のターミナル操作 → 切断、という通常の流れを録画して添付します。 + +iOSSH固有のアカウント登録、ログイン、アカウント削除はありません。ユーザー生成コンテンツをホストしないため、通報・ブロック機能もありません。有料デジタルコンテンツ、サブスクリプション、アプリ内課金はありません。 + +2. **目的と対象者** + +iOSSHはiPhoneとiPad用のSSHターミナルクライアントです。モバイル端末からサーバーへ接続する開発者、システム管理者、そのほかの技術者を対象としています。標準互換のターミナル、パスワードと対応秘密鍵による認証、Unicodeと日本語入力、外部キーボード、フォントとテーマの設定、Kitty Graphics表示、iPadで最大4つの同時セッションタブを提供します。 + +3. **設定手順と審査用認証情報** + +iOSSHアカウントは不要です。主機能は次の手順で確認できます。 + +1. iOSSHを起動して **Add Host** を選ぶ。 +2. App Store Connectにのみ記載したSSHホスト、ポート、ユーザー名を入力し、認証方式に **Password** を選ぶ。 +3. ホストを保存して選択し、審査用パスワードを入力する。初回はホスト鍵を確認して承認する。 +4. ターミナルでコマンドを実行する。終了時は閉じるボタン、または **Terminal options → Disconnect** を使う。 + +```text +SSH host: [APP STORE CONNECTにのみ記載] +Port: [APP STORE CONNECTにのみ記載] +Username: [APP STORE CONNECTにのみ記載] +Authentication: Password +Password: [APP STORE CONNECTにのみ記載] +``` + +認証情報は審査期間中有効に保ちます。Tailscale取り込みは任意であり、SSHターミナルの審査には不要です。確認する場合は、別途インストールしたTailscaleアプリと設定済みtailnetが必要です。**Import from Tailscale → Set Up Shortcut** で同梱ショートカットを追加し、**Fetch Devices** からTailscale公式の **Find Devices** ショートカットアクションを実行します。 + +4. **外部サービス、ツール、プラットフォーム** + +開発者が運営するバックエンド、アカウントサービス、解析、広告、決済、AIサービスはありません。主なネットワーク機能は、利用者が選択・管理するSSHサーバーへ直接接続します。Tailscaleは任意で、APIトークンを使わず、Tailscaleアプリと公式の **Find Devices** ショートカットアクションを介して利用します。Citadel、swift-nio-ssh、swift-crypto、SwiftTerm、libghostty-vtなど、SSH・暗号・ターミナル解析・描画のオープンソースライブラリを同梱しています。 + +5. **地域差** + +機能や動作に地域差はありません。配信するすべての地域で同じように動作します。英語・日本語の表示と同梱CJKフォントはローカライズ機能であり、地域制限ではありません。 + +6. **規制産業と第三者コンテンツ** + +iOSSHは汎用の開発者向けツールであり、規制産業のサービスではありません。ライセンスされた娯楽作品など、保護された第三者コンテンツは同梱しません。同梱する第三者ソフトウェアとフォントはオープンソースで、ライセンスは **Settings → Open source licenses** から確認できます。SSHセッション中に表示される内容は利用者が選んだサーバーから届くもので、iOSSHが提供するコンテンツではありません。 + +実際にAppleへ返信する際は、英語版の[Copy-ready response](APP_STORE.md#copy-ready-response)を使い、角括弧を置き換えます。 + +## 再提出チェックリスト + +- 専用の審査用SSHサーバーを審査期間中オンラインに保つ。ホスト、ポート、ユーザー名、パスワードはApp Store Connectだけに記載する。 +- 実機で、起動 → 審査用ホスト追加 → 接続 → ターミナル操作 → 切断の全手順を録画し、審査メッセージへ添付する。 +- 完成した回答を審査メッセージと **App Review Information → Notes** の両方へ貼り付ける。 +- 私用のホスト名、ユーザー名、IPアドレス、ターミナル履歴、第三者の映像が見えるストア画像は、審査用の安全なテストデータを使った画像へ差し替える。 +- 再提出前にApp Privacy、年齢区分、輸出コンプライアンス、価格、配信地域、プライバシーポリシーURL、サポートURL、審査連絡先、選択ビルドを再確認する。 + +## リリース記録と毎回の確認 + +- 公開済みの[プライバシーポリシー](PRIVACY.jp.md)と[サポートページ](SUPPORT.jp.md)のURLをApp Store Connectへ登録した状態に保ち、アプリ内の **Settings → About** と一致させる。 +- App Privacy、年齢区分、暗号化・輸出コンプライアンスの回答をリリースごとに確認する。SSHは依存ライブラリを通じて暗号処理を使う。`ITSAppUsesNonExemptEncryption` は、推測値ではなくApp Store Connectで明示的に回答するため、引き続き自動設定しない。 - **Settings → Open source licenses**で同梱ソフトウェアの表記と、別に用意したフォントのライセンスを確認する。ソフトウェアの表記は生成物であり、`scripts/generate_third_party_notices.py --check` が、アプリが実際にリンクしている依存関係との食い違いを検出して失敗する。`Package.resolved` に現れないまま全ビルドに含まれる libghostty-vt もこの対象に含めている。 -- 最終ビルドのiPhone・iPadで、私用サーバーの情報を含めず、テスト用接続先によるストア向けスクリーンショットを撮影する。[開発ノート](DEVELOPMENT.jp.md)の実機確認を完了する。 -- 審査担当者向けの連絡先と、動作するSSH接続情報を用意する。 +- 最終ビルドのiPhone・iPadで、私用サーバーの情報を含めず、審査用の安全なテスト接続先によるストア向けスクリーンショットを撮影する。[開発ノート](DEVELOPMENT.jp.md)の実機確認を完了する。 +- 提出ごとに審査担当者向けの連絡先と、有効なSSH接続情報を確認する。 Appleの資料:[アプリ情報の作成](https://developer.apple.com/help/app-store-connect/create-an-app-record/add-a-new-app)、[ビルドのアップロード](https://developer.apple.com/help/app-store-connect/manage-builds/upload-builds)、[App Review Guidelines](https://developer.apple.com/app-store/review/guidelines/)。 diff --git a/docs/APP_STORE.md b/docs/APP_STORE.md index b862dc7..7b5baf6 100644 --- a/docs/APP_STORE.md +++ b/docs/APP_STORE.md @@ -2,10 +2,10 @@ English | [日本語](APP_STORE.jp.md) -These fields describe the implemented app. A build has been uploaded to App -Store Connect but has not been submitted for review. The release uses the -individual Apple Developer membership and bundle identifier -`io.github.m96-chan.iossh`. +These fields describe the implemented app. The first submission was returned on +September 16, 2026 under Guideline 2.1 for additional review information; Apple +did not cite a defect in the binary. The release uses the individual Apple +Developer membership and bundle identifier `io.github.m96-chan.iossh`. This installs separately from previous `moe.technologies.iossh` development builds. Saved hosts, credentials, settings, and imported fonts do not migrate @@ -59,24 +59,123 @@ device import flow requires adding **Import Tailscale Hosts** from **Import from Tailscale → Set Up Shortcut**, then using **Fetch Devices** and selecting hosts before registration. -## Remaining release inputs - -- Confirm the store name's availability, primary language, price, and countries. -- Register the public [privacy policy](PRIVACY.md) and [support page](SUPPORT.md) - URLs in App Store Connect, and verify the matching links in the app's - **About** section. -- Complete App Privacy, the age rating, and encryption/export compliance answers - based on the shipped app. SSH uses cryptography through its dependencies; - `ITSAppUsesNonExemptEncryption` has not been guessed or set automatically. +## Guideline 2.1 review response + +Apple requested the following information for submission +`9afe9cac-389d-4f2d-bb18-7f378de6ccf3`. Paste the completed response both into +the App Store Connect conversation and **App Review Information → Notes**. +Replace every bracketed value there; the review server credentials and recording +must remain outside this repository. + +### Copy-ready response + +```text +Thank you for reviewing iOSSH. Please find the requested information below. + +1. Physical-device screen recording + +[Attach or link a recording made on a physical iPhone or iPad.] The recording +starts from app launch and shows the typical flow: adding the review SSH host, +connecting with the supplied credentials, using the live terminal, and +disconnecting. + +iOSSH has no app-specific account registration, login, or account deletion. +It does not host user-generated content and therefore has no reporting or +blocking flow. It has no paid digital content, subscriptions, or in-app +purchases. + +2. Purpose and target audience + +iOSSH is an SSH terminal client for iPhone and iPad. It is intended for +developers, system administrators, and other technical users who need to access +servers from a mobile device. Its main features are a standards-compatible +terminal, password and supported private-key authentication, Unicode and +Japanese input, hardware-keyboard support, configurable fonts and themes, +Kitty graphics display, and up to four simultaneous session tabs on iPad. + +3. Setup instructions and review credentials + +No iOSSH account is required. To test the main functionality: +1) Launch iOSSH and choose Add Host. +2) Enter the SSH host, port, username, and Password authentication shown below. +3) Save the host, select it, enter the supplied password, and approve the host + key when prompted. +4) Run commands in the terminal. Use the close button or Terminal options > + Disconnect when finished. + +SSH host: [APP STORE CONNECT ONLY] +Port: [APP STORE CONNECT ONLY] +Username: [APP STORE CONNECT ONLY] +Authentication: Password +Password: [APP STORE CONNECT ONLY] + +The credentials will remain active throughout the review. Tailscale import is +an optional feature and is not required to review the SSH terminal. If desired, +it requires the separately installed Tailscale app and a configured tailnet; +Import from Tailscale > Set Up Shortcut installs the bundled shortcut, and Fetch +Devices runs Tailscale's official Find Devices Shortcuts action. + +4. External services, tools, and platforms + +iOSSH has no developer-operated backend, account service, analytics service, +advertising service, payment processor, or AI service. Its core network function +connects directly to SSH servers selected and controlled by the user. Tailscale +is optional and is accessed through the Tailscale app and its official Find +Devices Shortcuts action without an API token. The app includes open-source SSH, +cryptography, terminal parsing, and rendering libraries, including Citadel, +swift-nio-ssh, swift-crypto, SwiftTerm, and libghostty-vt. + +5. Regional differences + +There are no regional differences in features or behavior. iOSSH functions +consistently in every region where it is distributed. English and Japanese text +support and the bundled CJK font are localization features, not regional +restrictions. + +6. Regulated industry and third-party material + +iOSSH is a general-purpose developer tool and does not operate in a regulated +industry. It does not bundle licensed entertainment or other protected +third-party content. Its bundled third-party software and fonts are open source, +and their license notices are available in Settings > Open source licenses. +Content displayed during an SSH session comes from a server selected by the +user and is not supplied by iOSSH. +``` + +## Resubmission checklist + +- Keep a dedicated review SSH server online for the entire review window. Put + its host, port, username, and password only in App Store Connect. +- Record the complete flow on a physical device: launch → add the review host → + connect → use the terminal → disconnect. Attach the recording to the review + reply. +- Paste the completed response above into both the review conversation and + **App Review Information → Notes**. +- Replace any store screenshot that exposes a private hostname, username, IP + address, terminal history, or third-party media. Screenshots must show the app + in use with review-safe test data. +- Reconfirm App Privacy, age rating, export compliance, pricing, availability, + privacy policy URL, support URL, review contact, and the selected build before + resubmitting. + +## Release records and recurring checks + +- The public [privacy policy](PRIVACY.md) and [support page](SUPPORT.md) must stay + registered in App Store Connect and match the links in **Settings → About**. +- App Privacy, age rating, and encryption/export compliance must be reviewed for + every release. SSH uses cryptography through its dependencies; + `ITSAppUsesNonExemptEncryption` remains deliberately unset so App Store + Connect receives an explicit answer rather than an inferred one. - Verify the shipped software notices under **Settings → Open source licenses** and the separate bundled font licenses. The software notices are generated; `scripts/generate_third_party_notices.py --check` fails when they drift from what the app links, including libghostty-vt, which ships in every build but has no `Package.resolved` pin to be discovered from. -- Capture store screenshots from the final iPhone and iPad build with test hosts - and no private server information. Complete the physical-device checks listed - in [development notes](DEVELOPMENT.md). -- Confirm the review contact and supply working SSH review access. +- Capture store screenshots from the final iPhone and iPad build with review-safe + test hosts and no private server information. Complete the physical-device + checks listed in [development notes](DEVELOPMENT.md). +- Confirm the review contact and working SSH review access before every + submission. Apple references: [Create an app record](https://developer.apple.com/help/app-store-connect/create-an-app-record/add-a-new-app), [upload builds](https://developer.apple.com/help/app-store-connect/manage-builds/upload-builds),