We have a standalone reproduction of encrypted Core ML model loading capacity decreasing after the app is terminated during an unfinished load.
Feedback ID: FB25001494
The Feedback Assistant report includes a minimal UIKit/Objective-C project, a small model generated entirely from seeded random constants, and 40 standalone experiment logs.
Environment
iPhone 14 Pro (iPhone15,2)
iOS 16.0 (20A357)
Both synchronous and asynchronous Core ML loading APIs
MLComputeUnitsAll
Loading runs on a background worker, with only one outstanding request during each interruption trial
No application-level loading timeout
Other iOS versions have not yet been verified with this standalone sample.
Error
NSError domain: com.apple.CoreML
Code: 9
The error description contains "Failed to set up decrypt context" and "error:-42905".
Reproduction
Reboot the device and complete normal model loading/releasing to ensure the encryption key is available.
Measure capacity by sequentially loading and retaining encrypted MLModel instances until the first failure, then release all successful instances.
Launch a fresh process and terminate it with SIGKILL approximately 50 ms after starting its first model load, before the load completes.
Repeat this interruption in five fresh processes.
Launch another process and measure capacity again.
Observed results
Initial capacity: 99, 99 in two measurements.
After five interrupted synchronous loads: 94, 94.
After five additional interrupted asynchronous loads: 90, 90.
After 40 normal asynchronous loads/releases: still 90, 90.
After five more interrupted synchronous loads: 85, 85.
After at least 60 seconds with no sample process running: still 85, 85.
After rebooting the device: 99, 99.
Timing matters: five interruptions at approximately 5 ms did not reduce capacity. We do not claim that every interrupted load loses exactly one resource.
Controls and interpretation
Normal controls and capacity probes release all successfully loaded models before their processes are terminated. Autorelease pools and associated-object deallocation witnesses are used to check model lifetime; these do not directly inspect internal decrypt sessions.
The capacity-limit error while deliberately retaining many models is expected. The unexpected behavior is that terminating an unfinished load reduces the repeatable capacity available to subsequent fresh processes.
This suggests a cleanup issue across process termination, but the internal cause has not been established.
Questions
Is this a known issue, and if it has been fixed, which iOS version contains the fix?
Is there a supported recovery mechanism that does not require rebooting the device?
Is there a recommended loading or lifecycle workaround? Switching between synchronous and asynchronous loading did not eliminate the behavior.
Has anyone reproduced this specific interrupted-load behavior on a newer iOS version?
Related discussions
https://developer.apple.com/forums/thread/740731
https://developer.apple.com/forums/thread/678599
We also reviewed thread 707622, where moving the autorelease pool inside the loop resolved retained-model exhaustion. Our sample includes release controls and specifically tests capacity after termination of an unfinished load.
0
0
35