React Native 0.68.5 iOS打包上传触发ITMS-90338,如何定位问题依赖?
问题:React Native应用上传App Store触发ITMS-90338私有API检测
应用在模拟器和真机运行正常,但归档上传后收到苹果通知,提示使用了非公开符号_SSL_CTX_set_options、_SSL_session_reused。项目是从RN 0.55迁移的遗留项目,依赖和Podfile配置如下,需定位引发问题的依赖包。
苹果团队通知内容
开发者您好:我们发现您近期提交的应用“APP NAME”3.2.6(18)存在一处或多处问题,请修正以下问题后重新提交。ITMS-90338:非公开API使用
- 您的应用中引用了非公开符号:_SSL_CTX_set_options、_SSL_session_reused。如果您源代码中的方法名称与上述私有Apple API匹配,修改方法名称将有助于避免未来提交时被标记。此外,上述一个或多个API可能位于应用中包含的静态库中,若如此,必须移除该库。
此致,App Store团队
项目依赖列表
"@react-native-community/async-storage": "1.9.0", "@react-native-community/cli-debugger-ui": "3.0.0", "@react-native-community/masked-view": "0.1.10", "@react-native-community/push-notification-ios": "1.10.1", "@react-navigation/bottom-tabs": "5.4.2", "@react-navigation/native": "5.3.0", "@react-navigation/stack": "5.3.3", "@voximplant/react-native-foreground-service": "3.0.2", "create-react-class": "^15.7.0", "crypto-js": "^3.1.9-1", "moment": "2.17.1", "patch-package": "6.2.2", "react": "17.0.2", "react-native": "0.68.5", "react-native-ble-manager": "8.4.3", "react-native-code-push": "6.2.0", "react-native-config": "^1.2.1", "react-native-device-info": "5.5.5", "react-native-exception-handler": "2.10.8", "react-native-gesture-handler": "1.10.3", "react-native-htmlview": "0.15.0", "react-native-linear-gradient": "2.5.6", "react-native-localize": "1.4.0", "react-native-push-notification": "8.1.1", "react-native-reanimated": "1.8.0", "react-native-restart": "0.0.15", "react-native-rss-parser": "1.4.0", "react-native-safe-area-context": "^1.0.0", "react-native-screens": "2.7.0", "react-native-splash-screen": "3.2.0", "react-native-svg": "12.1.0", "react-native-swiper": "1.6.0", "react-native-vector-icons": "6.6.0", "realm": "10.24.0"
Podfile配置
require_relative '../node_modules/react-native/scripts/react_native_pods' require_relative '../node_modules/@react-native-community/cli-platform-ios/native_modules' platform :ios, '11.0' target 'targetname' do config = use_native_modules! use_react_native!( :path => config[:reactNativePath], # to enable hermes on iOS, change `false` to `true` and then install pods :hermes_enabled => false ) # Enables Flipper. # # Note that if you have use_frameworks! enabled, Flipper will not work and # you should disable the next line. use_flipper!() post_install do |installer| react_native_post_install(installer) __apply_Xcode_12_5_M1_post_install_workaround(installer) end end
排查方法
1. 检查归档二进制文件的符号引用
完成归档后,定位.app文件并搜索私有符号:
- 打开Xcode Organizer,右键归档 →
Show in Finder - 右键
.app文件 →Show Package Contents - 终端进入该目录,执行命令:
nm -u YourAppName.app/YourAppName | grep "_SSL_CTX_set_options\|_SSL_session_reused"
该命令会输出引用目标符号的对象,缩小排查范围。
2. 遍历Pods静态库查找符号来源
进入项目ios/Pods目录,执行命令遍历所有静态库:
find . -name "*.a" -exec nm -u {} \; | grep "_SSL_CTX_set_options\|_SSL_session_reused"
此命令会找出包含私有符号的静态库,对应到具体依赖包。
3. 优先排查高风险依赖
从依赖特性来看,以下包涉及底层/网络操作,优先检查:
react-native-ble-manager:蓝牙功能可能涉及SSL底层调用realm:数据库同步可能用到网络请求相关库react-native-code-push:OTA更新涉及网络传输@voximplant/react-native-foreground-service:VoIP服务可能涉及SSL配置
4. 版本验证与升级
检查上述依赖的版本是否存在已知私有API问题,尝试升级到最新稳定版,或查看对应GitHub Issues是否有相关报告。
5. 移除依赖验证
逐个移除怀疑的依赖,重新归档后用苹果验证工具检测:
xcrun altool --validate-app -f YourApp.ipa -t ios -u yourAppleID -p yourPassword
确认移除哪个依赖后问题消失,即可定位目标包。
内容的提问来源于stack exchange,提问作者LMate
相关产品推荐
相关产品推荐

