macadmins / macadmins/python

Replace munki-pkg with swiftpkg for managed Python packaging

Abierto
#94 1 comentario 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Lenguaje dominante
Shell
Estrellas
257
Forks
29
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

## Objective
Migrate this repository's managed Python installer packaging to [codecarton/swiftpkg](https://github.com/codecarton/swiftpkg) and retire the munki-pkg build dependency.

## Current behavior
`build_python_framework_pkgs.zsh` downloads a pinned munki-pkg commit using `MP_SHA`, `MP_BINDIR`, and `MP_ZIP`. Its `build_pkg()` function generates `recommended/build-info.json`, stages `preinstall-cleanup`, invokes `munkipkg`, and moves the signed package into `outputs/`. Notarization and stapling run separately. Without an installer identity, the script skips package creation and still produces the framework ZIP.

## Implementation scope
- Select and pin a published swiftpkg CLI release compatible with Apple Silicon build hosts; verify the downloaded artifact against a pinned SHA-256 and document prerequisites.
- Replace the munki-pkg download, temporary paths, and invocation with swiftpkg; propagate failures clearly.
- Validate compatibility of every generated build-info setting, especially `ownership`, `suppress_bundle_relocation`, `preserve_xattr`, `distribution_style`, and `signing_info`. Implement equivalent behavior for any unsupported settings.
- Preserve the package identifier (`io.macadmins.python.recommended`), version derivation, output filename/location, payload layout, permissions, symlinks, extended attributes, and preinstall cleanup behavior.
- Preserve framework code signing and the existing installer signing/notarization/stapling sequence; avoid duplicate notarization.
- Ensure Python 3.11, 3.12, 3.13, and 3.14 workflows use the replacement and continue publishing expected artifacts; update workflows only where necessary.
- Update README build prerequisites and credits. Remove active munki-pkg dependencies and obsolete bootstrap references while retaining appropriate historical attribution.

## Acceptance criteria
- [ ] Local and CI packaging use the pinned swiftpkg CLI with verified artifact integrity; no active build path downloads or executes munki-pkg.
- [ ] All generated build-info options have verified equivalent behavior, with any migration differences documented.
- [ ] On Apple Silicon, inspect a baseline munki-pkg package and replacement package to confirm equivalent receipts, version, install paths, payload, ownership/modes, symlinks, extended attributes, installer scripts, and non-relocation behavior.
- [ ] Signed packages pass signature checks, notarization, and stapling validation using the existing signing credentials.
- [ ] Clean-install and upgrade smoke tests on a disposable Apple Silicon Mac confirm preinstall cleanup, framework installation at `/Library/ManagedFrameworks/Python/Python3.framework`, the `managed_python3` symlink, and execution/imports of the managed runtime and bundled dependencies.
- [ ] The no-installer-identity path continues producing the framework ZIP without requiring signing credentials.
- [ ] Each supported Python workflow builds and publishes the expected package artifact.
- [ ] `zsh -n build_python_framework_pkgs.zsh` passes; any modified workflow YAML parses successfully.
- [ ] README documents the replacement tool, pinned version/update procedure, and prerequisites.

## Boundaries
This change replaces the package builder. It does not remove support for deploying the resulting installer through Munki, change Python/runtime dependencies, add the Swiftpkgr desktop app, or change the managed framework's installation contract.

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Línea de trabajo

Empieza por build_python_framework_pkgs.zsh, especialmente por build_pkg(), las variables de bootstrap de munki-pkg y la generación existente de build-info.json. Después, inspecciona los archivos de workflow de Python 3.11–3.14 y los prerrequisitos del README. Compara los paquetes baseline y de reemplazo en Apple Silicon, y utiliza las comprobaciones indicadas de shell, firma, notarización, smoke test y artefactos para verificar que se ha completado.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
shell
Área
build-system, ci-cd, tooling
Tipo de issue
Refactorización
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Activo
Claridad
Bastante claro
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.