Replace munki-pkg with swiftpkg for managed Python packaging
Chưa có ai nhận issue này.
- Ngôn ngữ chính
- Shell
- Star
- 257
- Fork
- 29
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
## Objective
Migrate this repository's managed Python installer packaging to [codecarton/swiftpkg](https://github.com/codecarton/swiftpkg) and retire the munki-pkg build dependency.
## Current behavior
`build_python_framework_pkgs.zsh` downloads a pinned munki-pkg commit using `MP_SHA`, `MP_BINDIR`, and `MP_ZIP`. Its `build_pkg()` function generates `recommended/build-info.json`, stages `preinstall-cleanup`, invokes `munkipkg`, and moves the signed package into `outputs/`. Notarization and stapling run separately. Without an installer identity, the script skips package creation and still produces the framework ZIP.
## Implementation scope
- Select and pin a published swiftpkg CLI release compatible with Apple Silicon build hosts; verify the downloaded artifact against a pinned SHA-256 and document prerequisites.
- Replace the munki-pkg download, temporary paths, and invocation with swiftpkg; propagate failures clearly.
- Validate compatibility of every generated build-info setting, especially `ownership`, `suppress_bundle_relocation`, `preserve_xattr`, `distribution_style`, and `signing_info`. Implement equivalent behavior for any unsupported settings.
- Preserve the package identifier (`io.macadmins.python.recommended`), version derivation, output filename/location, payload layout, permissions, symlinks, extended attributes, and preinstall cleanup behavior.
- Preserve framework code signing and the existing installer signing/notarization/stapling sequence; avoid duplicate notarization.
- Ensure Python 3.11, 3.12, 3.13, and 3.14 workflows use the replacement and continue publishing expected artifacts; update workflows only where necessary.
- Update README build prerequisites and credits. Remove active munki-pkg dependencies and obsolete bootstrap references while retaining appropriate historical attribution.
## Acceptance criteria
- [ ] Local and CI packaging use the pinned swiftpkg CLI with verified artifact integrity; no active build path downloads or executes munki-pkg.
- [ ] All generated build-info options have verified equivalent behavior, with any migration differences documented.
- [ ] On Apple Silicon, inspect a baseline munki-pkg package and replacement package to confirm equivalent receipts, version, install paths, payload, ownership/modes, symlinks, extended attributes, installer scripts, and non-relocation behavior.
- [ ] Signed packages pass signature checks, notarization, and stapling validation using the existing signing credentials.
- [ ] Clean-install and upgrade smoke tests on a disposable Apple Silicon Mac confirm preinstall cleanup, framework installation at `/Library/ManagedFrameworks/Python/Python3.framework`, the `managed_python3` symlink, and execution/imports of the managed runtime and bundled dependencies.
- [ ] The no-installer-identity path continues producing the framework ZIP without requiring signing credentials.
- [ ] Each supported Python workflow builds and publishes the expected package artifact.
- [ ] `zsh -n build_python_framework_pkgs.zsh` passes; any modified workflow YAML parses successfully.
- [ ] README documents the replacement tool, pinned version/update procedure, and prerequisites.
## Boundaries
This change replaces the package builder. It does not remove support for deploying the resulting installer through Munki, change Python/runtime dependencies, add the Swiftpkgr desktop app, or change the managed framework's installation contract.
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Hướng nghiên cứu
Bắt đầu với build_python_framework_pkgs.zsh, đặc biệt là build_pkg(), các biến bootstrap của munki-pkg và việc tạo build-info.json hiện có. Sau đó, kiểm tra các tệp workflow của Python 3.11–3.14 và các điều kiện tiên quyết trong README. So sánh các package baseline và package thay thế trên Apple Silicon, đồng thời sử dụng các kiểm tra shell, ký, notarization, smoke test và artifact được liệt kê để xác minh việc hoàn tất.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- shell
- Lĩnh vực
- build-system, ci-cd, tooling
- Loại issue
- Tái cấu trúc
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức độ hoạt động
- Sôi nổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 35/100