You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

React Native 0.68.5 iOS打包上传触发ITMS-90338,如何定位问题依赖?

问题:React Native应用上传App Store触发ITMS-90338私有API检测

应用在模拟器和真机运行正常,但归档上传后收到苹果通知,提示使用了非公开符号_SSL_CTX_set_options、_SSL_session_reused。项目是从RN 0.55迁移的遗留项目,依赖和Podfile配置如下,需定位引发问题的依赖包。

苹果团队通知内容

开发者您好:我们发现您近期提交的应用“APP NAME”3.2.6(18)存在一处或多处问题,请修正以下问题后重新提交。ITMS-90338:非公开API使用

  • 您的应用中引用了非公开符号:_SSL_CTX_set_options、_SSL_session_reused。如果您源代码中的方法名称与上述私有Apple API匹配,修改方法名称将有助于避免未来提交时被标记。此外,上述一个或多个API可能位于应用中包含的静态库中,若如此,必须移除该库。
    此致,App Store团队

项目依赖列表

"@react-native-community/async-storage": "1.9.0",
"@react-native-community/cli-debugger-ui": "3.0.0",
"@react-native-community/masked-view": "0.1.10",
"@react-native-community/push-notification-ios": "1.10.1",
"@react-navigation/bottom-tabs": "5.4.2",
"@react-navigation/native": "5.3.0",
"@react-navigation/stack": "5.3.3",
"@voximplant/react-native-foreground-service": "3.0.2",
"create-react-class": "^15.7.0",
"crypto-js": "^3.1.9-1",
"moment": "2.17.1",
"patch-package": "6.2.2",
"react": "17.0.2",
"react-native": "0.68.5",
"react-native-ble-manager": "8.4.3",
"react-native-code-push": "6.2.0",
"react-native-config": "^1.2.1",
"react-native-device-info": "5.5.5",
"react-native-exception-handler": "2.10.8",
"react-native-gesture-handler": "1.10.3",
"react-native-htmlview": "0.15.0",
"react-native-linear-gradient": "2.5.6",
"react-native-localize": "1.4.0",
"react-native-push-notification": "8.1.1",
"react-native-reanimated": "1.8.0",
"react-native-restart": "0.0.15",
"react-native-rss-parser": "1.4.0",
"react-native-safe-area-context": "^1.0.0",
"react-native-screens": "2.7.0",
"react-native-splash-screen": "3.2.0",
"react-native-svg": "12.1.0",
"react-native-swiper": "1.6.0",
"react-native-vector-icons": "6.6.0",
"realm": "10.24.0"

Podfile配置

require_relative '../node_modules/react-native/scripts/react_native_pods'
require_relative '../node_modules/@react-native-community/cli-platform-ios/native_modules'

platform :ios, '11.0'

target 'targetname' do
  config = use_native_modules!

  use_react_native!(
    :path => config[:reactNativePath],
    # to enable hermes on iOS, change `false` to `true` and then install pods
    :hermes_enabled => false
  )

  # Enables Flipper.
  #
  # Note that if you have use_frameworks! enabled, Flipper will not work and
  # you should disable the next line.
  use_flipper!()

  post_install do |installer|
    react_native_post_install(installer)
    __apply_Xcode_12_5_M1_post_install_workaround(installer)
  end
end

排查方法

1. 检查归档二进制文件的符号引用

完成归档后,定位.app文件并搜索私有符号:

  • 打开Xcode Organizer,右键归档 → Show in Finder
  • 右键.app文件 → Show Package Contents
  • 终端进入该目录,执行命令:
nm -u YourAppName.app/YourAppName | grep "_SSL_CTX_set_options\|_SSL_session_reused"

该命令会输出引用目标符号的对象,缩小排查范围。

2. 遍历Pods静态库查找符号来源

进入项目ios/Pods目录,执行命令遍历所有静态库:

find . -name "*.a" -exec nm -u {} \; | grep "_SSL_CTX_set_options\|_SSL_session_reused"

此命令会找出包含私有符号的静态库,对应到具体依赖包。

3. 优先排查高风险依赖

从依赖特性来看,以下包涉及底层/网络操作,优先检查:

  • react-native-ble-manager:蓝牙功能可能涉及SSL底层调用
  • realm:数据库同步可能用到网络请求相关库
  • react-native-code-push:OTA更新涉及网络传输
  • @voximplant/react-native-foreground-service:VoIP服务可能涉及SSL配置

4. 版本验证与升级

检查上述依赖的版本是否存在已知私有API问题,尝试升级到最新稳定版,或查看对应GitHub Issues是否有相关报告。

5. 移除依赖验证

逐个移除怀疑的依赖,重新归档后用苹果验证工具检测:

xcrun altool --validate-app -f YourApp.ipa -t ios -u yourAppleID -p yourPassword

确认移除哪个依赖后问题消失,即可定位目标包。

内容的提问来源于stack exchange,提问作者LMate

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 20:15:32