16306: Merge branch 'master'
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         "errors"
12         "flag"
13         "fmt"
14         "io"
15         "os"
16         "os/exec"
17         "os/user"
18         "path/filepath"
19         "strconv"
20         "strings"
21         "syscall"
22         "time"
23
24         "git.arvados.org/arvados.git/lib/cmd"
25         "git.arvados.org/arvados.git/sdk/go/ctxlog"
26         "github.com/lib/pq"
27 )
28
29 var Command cmd.Handler = &installCommand{}
30
31 const devtestDatabasePassword = "insecure_arvados_test"
32
33 type installCommand struct {
34         ClusterType    string
35         SourcePath     string
36         PackageVersion string
37 }
38
39 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
40         logger := ctxlog.New(stderr, "text", "info")
41         ctx := ctxlog.Context(context.Background(), logger)
42         ctx, cancel := context.WithCancel(ctx)
43         defer cancel()
44
45         var err error
46         defer func() {
47                 if err != nil {
48                         logger.WithError(err).Info("exiting")
49                 }
50         }()
51
52         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
53         flags.SetOutput(stderr)
54         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
55         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
56         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
57         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
58         err = flags.Parse(args)
59         if err == flag.ErrHelp {
60                 err = nil
61                 return 0
62         } else if err != nil {
63                 return 2
64         } else if *versionFlag {
65                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
66         } else if len(flags.Args()) > 0 {
67                 err = fmt.Errorf("unrecognized command line arguments: %v", flags.Args())
68                 return 2
69         }
70
71         var dev, test, prod, pkg bool
72         switch inst.ClusterType {
73         case "development":
74                 dev = true
75         case "test":
76                 test = true
77         case "production":
78                 prod = true
79         case "package":
80                 pkg = true
81         default:
82                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
83                 return 2
84         }
85
86         if prod {
87                 err = errors.New("production install is not yet implemented")
88                 return 1
89         }
90
91         osv, err := identifyOS()
92         if err != nil {
93                 return 1
94         }
95
96         listdir, err := os.Open("/var/lib/apt/lists")
97         if err != nil {
98                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
99         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
100                 // Special case for a base docker image where the
101                 // package cache has been deleted and all "apt-get
102                 // install" commands will fail unless we fetch repos.
103                 cmd := exec.CommandContext(ctx, "apt-get", "update")
104                 cmd.Stdout = stdout
105                 cmd.Stderr = stderr
106                 err = cmd.Run()
107                 if err != nil {
108                         return 1
109                 }
110         }
111
112         pkgs := prodpkgs(osv)
113
114         if pkg {
115                 pkgs = append(pkgs,
116                         "dpkg-dev",
117                         "rsync",
118                 )
119         }
120
121         if dev || test || pkg {
122                 pkgs = append(pkgs,
123                         "automake",
124                         "bison",
125                         "bsdmainutils",
126                         "build-essential",
127                         "cadaver",
128                         "curl",
129                         "cython3",
130                         "daemontools", // lib/boot uses setuidgid to drop privileges when running as root
131                         "default-jdk-headless",
132                         "default-jre-headless",
133                         "gettext",
134                         "iceweasel",
135                         "libattr1-dev",
136                         "libcrypt-ssleay-perl",
137                         "libfuse-dev",
138                         "libgnutls28-dev",
139                         "libjson-perl",
140                         "libpam-dev",
141                         "libpcre3-dev",
142                         "libpq-dev",
143                         "libreadline-dev",
144                         "libssl-dev",
145                         "libwww-perl",
146                         "libxml2-dev",
147                         "libxslt1-dev",
148                         "linkchecker",
149                         "lsof",
150                         "make",
151                         "net-tools",
152                         "pandoc",
153                         "perl-modules",
154                         "pkg-config",
155                         "postgresql",
156                         "postgresql-contrib",
157                         "python3-dev",
158                         "python3-venv",
159                         "python3-virtualenv",
160                         "r-base",
161                         "r-cran-testthat",
162                         "r-cran-devtools",
163                         "r-cran-knitr",
164                         "r-cran-markdown",
165                         "r-cran-roxygen2",
166                         "r-cran-xml",
167                         "sudo",
168                         "wget",
169                         "xvfb",
170                 )
171                 switch {
172                 case osv.Debian && osv.Major >= 10:
173                         pkgs = append(pkgs, "libcurl4")
174                 default:
175                         pkgs = append(pkgs, "libcurl3")
176                 }
177                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends")
178                 cmd.Args = append(cmd.Args, pkgs...)
179                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
180                 cmd.Stdout = stdout
181                 cmd.Stderr = stderr
182                 err = cmd.Run()
183                 if err != nil {
184                         return 1
185                 }
186         }
187
188         os.Mkdir("/var/lib/arvados", 0755)
189         os.Mkdir("/var/lib/arvados/tmp", 0700)
190         if prod || pkg {
191                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
192                 u, er := user.Lookup("www-data")
193                 if er != nil {
194                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
195                         return 1
196                 }
197                 uid, _ := strconv.Atoi(u.Uid)
198                 gid, _ := strconv.Atoi(u.Gid)
199                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
200                 if err != nil {
201                         return 1
202                 }
203         }
204         rubyversion := "2.5.7"
205         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+rubyversion)) {
206                 logger.Print("ruby " + rubyversion + " already installed")
207         } else {
208                 err = runBash(`
209 tmp=/var/lib/arvados/tmp/ruby-`+rubyversion+`
210 trap "rm -r ${tmp}" ERR
211 wget --progress=dot:giga -O- https://cache.ruby-lang.org/pub/ruby/2.5/ruby-`+rubyversion+`.tar.gz | tar -C /var/lib/arvados/tmp -xzf -
212 cd ${tmp}
213 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
214 make -j8
215 make install
216 /var/lib/arvados/bin/gem install bundler --no-ri --no-rdoc
217 # "gem update --system" can be removed when we use ruby â‰¥2.6.3: https://bundler.io/blog/2019/05/14/solutions-for-cant-find-gem-bundler-with-executable-bundle.html
218 /var/lib/arvados/bin/gem update --system --no-ri --no-rdoc
219 rm -r ${tmp}
220 `, stdout, stderr)
221                 if err != nil {
222                         return 1
223                 }
224         }
225
226         if !prod {
227                 goversion := "1.14"
228                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
229                         logger.Print("go " + goversion + " already installed")
230                 } else {
231                         err = runBash(`
232 cd /tmp
233 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
234 ln -sf /var/lib/arvados/go/bin/* /usr/local/bin/
235 `, stdout, stderr)
236                         if err != nil {
237                                 return 1
238                         }
239                 }
240         }
241
242         if !prod && !pkg {
243                 pjsversion := "1.9.8"
244                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
245                         logger.Print("phantomjs " + pjsversion + " already installed")
246                 } else {
247                         err = runBash(`
248 PJS=phantomjs-`+pjsversion+`-linux-x86_64
249 wget --progress=dot:giga -O- https://bitbucket.org/ariya/phantomjs/downloads/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
250 ln -sf /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
251 `, stdout, stderr)
252                         if err != nil {
253                                 return 1
254                         }
255                 }
256
257                 geckoversion := "0.24.0"
258                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
259                         logger.Print("geckodriver " + geckoversion + " already installed")
260                 } else {
261                         err = runBash(`
262 GD=v`+geckoversion+`
263 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
264 ln -sf /var/lib/arvados/bin/geckodriver /usr/local/bin/
265 `, stdout, stderr)
266                         if err != nil {
267                                 return 1
268                         }
269                 }
270
271                 nodejsversion := "v8.15.1"
272                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == nodejsversion+"\n" {
273                         logger.Print("nodejs " + nodejsversion + " already installed")
274                 } else {
275                         err = runBash(`
276 NJS=`+nodejsversion+`
277 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
278 ln -sf /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
279 `, stdout, stderr)
280                         if err != nil {
281                                 return 1
282                         }
283                 }
284
285                 gradleversion := "5.3.1"
286                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
287                         logger.Print("gradle " + gradleversion + " already installed")
288                 } else {
289                         err = runBash(`
290 G=`+gradleversion+`
291 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
292 trap "rm ${zip}" ERR
293 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
294 unzip -o -d /var/lib/arvados ${zip}
295 ln -sf /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
296 rm ${zip}
297 `, stdout, stderr)
298                         if err != nil {
299                                 return 1
300                         }
301                 }
302
303                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
304                 // it's installed, locale -a reports it as
305                 // "en_US.utf8".
306                 wantlocale := "en_US.UTF-8"
307                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
308                         logger.Print("locale " + wantlocale + " already installed")
309                 } else {
310                         err = runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
311                         if err != nil {
312                                 return 1
313                         }
314                 }
315
316                 var pgc struct {
317                         Version       string
318                         Cluster       string
319                         Port          int
320                         Status        string
321                         Owner         string
322                         DataDirectory string
323                         LogFile       string
324                 }
325                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
326                         err = fmt.Errorf("pg_lsclusters: %s", err2)
327                         return 1
328                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
329                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
330                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
331                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
332                         return 1
333                 } else if pgc.Status == "online" {
334                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
335                 } else {
336                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
337                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
338                         cmd.Stdout = stdout
339                         cmd.Stderr = stderr
340                         err = cmd.Start()
341                         if err != nil {
342                                 return 1
343                         }
344                         defer func() {
345                                 cmd.Process.Signal(syscall.SIGTERM)
346                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
347                                 cmd.Wait()
348                         }()
349                         err = waitPostgreSQLReady()
350                         if err != nil {
351                                 return 1
352                         }
353                 }
354
355                 if os.Getpid() == 1 {
356                         // We are the init process (presumably in a
357                         // docker container) so although postgresql is
358                         // installed, it's not running, and initdb
359                         // might never have been run.
360                 }
361
362                 var needcoll []string
363                 // If the en_US.UTF-8 locale wasn't installed when
364                 // postgresql initdb ran, it needs to be added
365                 // explicitly before we can use it in our test suite.
366                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
367                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
368                         cmd.Dir = "/"
369                         out, err2 := cmd.CombinedOutput()
370                         if err != nil {
371                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
372                                 return 1
373                         }
374                         if strings.Contains(string(out), "1") {
375                                 logger.Infof("postgresql supports collation %s", collname)
376                         } else {
377                                 needcoll = append(needcoll, collname)
378                         }
379                 }
380                 if len(needcoll) > 0 && os.Getpid() != 1 {
381                         // In order for the CREATE COLLATION statement
382                         // below to work, the locale must have existed
383                         // when PostgreSQL started up. If we're
384                         // running as init, we must have started
385                         // PostgreSQL ourselves after installing the
386                         // locales. Otherwise, it might need a
387                         // restart, so we attempt to restart it with
388                         // systemd.
389                         if err = runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
390                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
391                         } else if err = waitPostgreSQLReady(); err != nil {
392                                 return 1
393                         }
394                 }
395                 for _, collname := range needcoll {
396                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
397                         cmd.Stdout = stdout
398                         cmd.Stderr = stderr
399                         cmd.Dir = "/"
400                         err = cmd.Run()
401                         if err != nil {
402                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
403                                 return 1
404                         }
405                 }
406
407                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
408                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
409                 cmd.Dir = "/"
410                 if err := cmd.Run(); err == nil {
411                         logger.Print("arvados role exists; superuser privileges added, password updated")
412                 } else {
413                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
414                         cmd.Dir = "/"
415                         cmd.Stdout = stdout
416                         cmd.Stderr = stderr
417                         err = cmd.Run()
418                         if err != nil {
419                                 return 1
420                         }
421                 }
422         }
423
424         if prod || pkg {
425                 // Install Rails apps to /var/lib/arvados/{railsapi,workbench1}/
426                 for dstdir, srcdir := range map[string]string{
427                         "railsapi":   "services/api",
428                         "workbench1": "apps/workbench",
429                 } {
430                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
431                         cmd := exec.Command("rsync",
432                                 "-a", "--no-owner", "--delete-after", "--delete-excluded",
433                                 "--exclude", "/coverage",
434                                 "--exclude", "/log",
435                                 "--exclude", "/tmp",
436                                 "--exclude", "/vendor",
437                                 "./", "/var/lib/arvados/"+dstdir+"/")
438                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
439                         cmd.Stdout = stdout
440                         cmd.Stderr = stderr
441                         err = cmd.Run()
442                         if err != nil {
443                                 return 1
444                         }
445                         for _, cmdline := range [][]string{
446                                 {"mkdir", "-p", "log", "tmp", ".bundle", "/var/www/.gem", "/var/www/.bundle", "/var/www/.passenger"},
447                                 {"touch", "log/production.log"},
448                                 {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.gem", "/var/www/.bundle", "/var/www/.passenger", "log", "tmp", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
449                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:1.16.6", "bundler:1.17.3", "bundler:2.0.2"},
450                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--deployment", "--jobs", "8", "--path", "/var/www/.gem"},
451                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
452                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
453                         } {
454                                 cmd = exec.Command(cmdline[0], cmdline[1:]...)
455                                 cmd.Env = append([]string{}, os.Environ()...)
456                                 cmd.Dir = "/var/lib/arvados/" + dstdir
457                                 cmd.Stdout = stdout
458                                 cmd.Stderr = stderr
459                                 fmt.Fprintf(stderr, "... %s\n", cmd.Args)
460                                 err = cmd.Run()
461                                 if err != nil {
462                                         return 1
463                                 }
464                         }
465                         cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
466                         cmd.Dir = "/var/lib/arvados/" + dstdir
467                         cmd.Stdout = stdout
468                         cmd.Stderr = stderr
469                         err = cmd.Run()
470                         if err != nil && !strings.Contains(err.Error(), "exit status 2") {
471                                 // Exit code 2 indicates there were warnings (like
472                                 // "other passenger installations have been detected",
473                                 // which we can't expect to avoid) but no errors.
474                                 // Other non-zero exit codes (1, 9) indicate errors.
475                                 return 1
476                         }
477                 }
478
479                 // Install Go programs to /var/lib/arvados/bin/
480                 for _, srcdir := range []string{
481                         "cmd/arvados-client",
482                         "cmd/arvados-server",
483                         "services/arv-git-httpd",
484                         "services/crunch-dispatch-local",
485                         "services/crunch-dispatch-slurm",
486                         "services/health",
487                         "services/keep-balance",
488                         "services/keep-web",
489                         "services/keepproxy",
490                         "services/keepstore",
491                         "services/ws",
492                 } {
493                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
494                         cmd := exec.Command("go", "install", "-ldflags", "-X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+" -X main.version="+inst.PackageVersion)
495                         cmd.Env = append([]string{"GOBIN=/var/lib/arvados/bin"}, os.Environ()...)
496                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
497                         cmd.Stdout = stdout
498                         cmd.Stderr = stderr
499                         err = cmd.Run()
500                         if err != nil {
501                                 return 1
502                         }
503                 }
504
505                 // Copy assets from source tree to /var/lib/arvados/share
506                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
507                 cmd.Stdout = stdout
508                 cmd.Stderr = stderr
509                 err = cmd.Run()
510                 if err != nil {
511                         return 1
512                 }
513         }
514
515         return 0
516 }
517
518 type osversion struct {
519         Debian bool
520         Ubuntu bool
521         Centos bool
522         Major  int
523 }
524
525 func identifyOS() (osversion, error) {
526         var osv osversion
527         f, err := os.Open("/etc/os-release")
528         if err != nil {
529                 return osv, err
530         }
531         defer f.Close()
532
533         kv := map[string]string{}
534         scanner := bufio.NewScanner(f)
535         for scanner.Scan() {
536                 line := strings.TrimSpace(scanner.Text())
537                 if strings.HasPrefix(line, "#") {
538                         continue
539                 }
540                 toks := strings.SplitN(line, "=", 2)
541                 if len(toks) != 2 {
542                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
543                 }
544                 k := toks[0]
545                 v := strings.Trim(toks[1], `"`)
546                 if v == toks[1] {
547                         v = strings.Trim(v, `'`)
548                 }
549                 kv[k] = v
550         }
551         if err = scanner.Err(); err != nil {
552                 return osv, err
553         }
554         switch kv["ID"] {
555         case "ubuntu":
556                 osv.Ubuntu = true
557         case "debian":
558                 osv.Debian = true
559         case "centos":
560                 osv.Centos = true
561         default:
562                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
563         }
564         vstr := kv["VERSION_ID"]
565         if i := strings.Index(vstr, "."); i > 0 {
566                 vstr = vstr[:i]
567         }
568         osv.Major, err = strconv.Atoi(vstr)
569         if err != nil {
570                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
571         }
572         return osv, nil
573 }
574
575 func waitPostgreSQLReady() error {
576         for deadline := time.Now().Add(10 * time.Second); ; {
577                 output, err := exec.Command("pg_isready").CombinedOutput()
578                 if err == nil {
579                         return nil
580                 } else if time.Now().After(deadline) {
581                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
582                 } else {
583                         time.Sleep(time.Second)
584                 }
585         }
586 }
587
588 func runBash(script string, stdout, stderr io.Writer) error {
589         cmd := exec.Command("bash", "-")
590         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
591         cmd.Stdout = stdout
592         cmd.Stderr = stderr
593         return cmd.Run()
594 }
595
596 func prodpkgs(osv osversion) []string {
597         pkgs := []string{
598                 "ca-certificates",
599                 "curl",
600                 "fuse",
601                 "git",
602                 "gitolite3",
603                 "graphviz",
604                 "haveged",
605                 "libcurl3-gnutls",
606                 "libxslt1.1",
607                 "nginx",
608                 "python",
609                 "sudo",
610         }
611         if osv.Debian || osv.Ubuntu {
612                 if osv.Debian && osv.Major == 8 {
613                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
614                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
615                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
616                 }
617                 return append(pkgs,
618                         "g++",
619                         "libcurl4-openssl-dev", // services/api
620                         "libpq-dev",
621                         "libpython2.7", // services/fuse
622                         "mime-support", // keep-web
623                         "zlib1g-dev",   // services/api
624                 )
625         } else if osv.Centos {
626                 return append(pkgs,
627                         "fuse-libs", // services/fuse
628                         "gcc",
629                         "gcc-c++",
630                         "libcurl-devel",    // services/api
631                         "mailcap",          // keep-web
632                         "postgresql-devel", // services/api
633                 )
634         } else {
635                 panic("os version not supported")
636         }
637 }
638
639 func ProductionDependencies() ([]string, error) {
640         osv, err := identifyOS()
641         if err != nil {
642                 return nil, err
643         }
644         return prodpkgs(osv), nil
645 }