Skip to content

fix(iOS): embed the dynamic frameworks of spm_dependency Swift packages - #58781

Closed
mfazekas wants to merge 1 commit into
react:mainfrom
mfazekas:feat/spm-embed-frameworks
Closed

mfazekas wants to merge 1 commit into
react:mainfrom
mfazekas:feat/spm-embed-frameworks

Conversation

@mfazekas

@mfazekas mfazekas commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Summary:

spm_dependency links a pod against Swift package products, but CocoaPods only embeds the frameworks of pods. Dynamic frameworks from Swift packages (binary targets like rive-ios' RiveRuntime, or type: .dynamic products like AlamofireDynamic) never reach the app bundle, so the app builds but fails at launch with dyld: Library not loaded: @rpath/RiveRuntime.framework/RiveRuntime. Separately, Xcode 26 archives fail on the duplicate signature Xcode writes for a binary target used by a pod: "RiveRuntime.xcframework-ios.signature" couldn't be copied to "Signatures" because an item with the same name already exists.

This PR:

  1. Adds an install_spm_framework <name> call per framework to the app's [CP] Embed Pods Frameworks script, which embeds the framework from where Xcode builds it, unless it is static.
  2. Adds embed_frameworks: to spm_dependency, defaulting to products, for frameworks named differently from their product (Sentry-Dynamic is Sentry.framework) or coming from the packages a product depends on (MapboxMaps loads MapboxCommon, MapboxCoreMaps and Turf).
  3. Removes the pod's duplicate *.xcframework-*.signature for pods not built into the shared products dir.
  4. Records a dependency once, even though CocoaPods evaluates a podspec several times per install.

Libraries work around this on their own today, e.g. react-native-firebase's firebase_spm.rb, stripe/stripe-react-native#2608, maplibre/maplibre-react-native#1490, or by dropping SPM as in getsentry/sentry-react-native#6381.

Changelog:

[IOS] [FIXED] - spm_dependency embeds the dynamic frameworks of Swift packages in the app, and takes embed_frameworks for frameworks named differently from their product

Test Plan:

ruby -Itest packages/react-native/scripts/cocoapods/__tests__/spm-test.rb passes, with 5 new tests. It also fixes the existing tests, whose installer stub lacked aggregate_targets since #57602.

Built https://github.com/mfazekas/rn-spm-dynamic-poc (a library using AlamofireDynamic, RiveRuntime and Sentry-Dynamic) with this spm.rb on RN 0.84 and Xcode 26.5:

  • Before: Debug simulator launch fails with Library not loaded: @rpath/RiveRuntime.framework, and the Release archive fails on the duplicate signature.
  • After: the frameworks are embedded, the app launches and the archive succeeds, with dynamic frameworks (all three) and with static libraries (RiveRuntime and Sentry; AlamofireDynamic does not link statically, with or without this change).

Its more-packages branch does the same with Agora, Mapbox, Stripe and Firebase.

CocoaPods only embeds the frameworks of pods, so a dynamic framework that a
Swift package adds through spm_dependency is linked but missing from the app
bundle, and the app fails at launch with dyld "Library not loaded". Add them
to the embed frameworks script, and remove the pod's duplicate xcframework
signature that fails Xcode 26 archives. The new embed_frameworks argument
names frameworks that differ from their product (Sentry-Dynamic is
Sentry.framework).
@meta-cla meta-cla Bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Oct 1, 2026
@facebook-github-tools facebook-github-tools Bot added the Shared with Meta Applied via automation to indicate that an Issue or Pull Request has been shared with the team. label Oct 1, 2026

@cipolleschi cipolleschi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing this!

@meta-codesync

meta-codesync Bot commented Oct 1, 2026

Copy link
Copy Markdown

@cipolleschi has imported this pull request. If you are a Meta employee, you can view this in D122772893.

@cortinico cortinico left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review automatically exported from Phabricator review in Meta.

@meta-codesync meta-codesync Bot closed this in d787826 Oct 1, 2026
@meta-codesync meta-codesync Bot added the Merged This PR has been merged. label Oct 1, 2026
@meta-codesync

meta-codesync Bot commented Oct 1, 2026

Copy link
Copy Markdown

@cipolleschi merged this pull request in d787826.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. Merged This PR has been merged. Shared with Meta Applied via automation to indicate that an Issue or Pull Request has been shared with the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants