18313: Merge branch 'main' into 18313-arvbox-bootstrap-go-version
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         "errors"
12         "flag"
13         "fmt"
14         "io"
15         "os"
16         "os/exec"
17         "os/user"
18         "path/filepath"
19         "strconv"
20         "strings"
21         "syscall"
22         "time"
23
24         "git.arvados.org/arvados.git/lib/cmd"
25         "git.arvados.org/arvados.git/sdk/go/ctxlog"
26         "github.com/lib/pq"
27 )
28
29 var Command cmd.Handler = &installCommand{}
30
31 const devtestDatabasePassword = "insecure_arvados_test"
32 const goversion = "1.17.1"
33
34 type installCommand struct {
35         ClusterType    string
36         SourcePath     string
37         PackageVersion string
38         EatMyData      bool
39 }
40
41 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
42         logger := ctxlog.New(stderr, "text", "info")
43         ctx := ctxlog.Context(context.Background(), logger)
44         ctx, cancel := context.WithCancel(ctx)
45         defer cancel()
46
47         var err error
48         defer func() {
49                 if err != nil {
50                         logger.WithError(err).Info("exiting")
51                 }
52         }()
53
54         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
55         flags.SetOutput(stderr)
56         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
57         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
58         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
59         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
60         flags.BoolVar(&inst.EatMyData, "eatmydata", false, "use eatmydata to speed up install")
61         err = flags.Parse(args)
62         if err == flag.ErrHelp {
63                 err = nil
64                 return 0
65         } else if err != nil {
66                 return 2
67         } else if *versionFlag {
68                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
69         } else if len(flags.Args()) > 0 {
70                 err = fmt.Errorf("unrecognized command line arguments: %v", flags.Args())
71                 return 2
72         }
73
74         var dev, test, prod, pkg bool
75         switch inst.ClusterType {
76         case "development":
77                 dev = true
78         case "test":
79                 test = true
80         case "production":
81                 prod = true
82         case "package":
83                 pkg = true
84         default:
85                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
86                 return 2
87         }
88
89         if prod {
90                 err = errors.New("production install is not yet implemented")
91                 return 1
92         }
93
94         osv, err := identifyOS()
95         if err != nil {
96                 return 1
97         }
98
99         listdir, err := os.Open("/var/lib/apt/lists")
100         if err != nil {
101                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
102         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
103                 // Special case for a base docker image where the
104                 // package cache has been deleted and all "apt-get
105                 // install" commands will fail unless we fetch repos.
106                 cmd := exec.CommandContext(ctx, "apt-get", "update")
107                 cmd.Stdout = stdout
108                 cmd.Stderr = stderr
109                 err = cmd.Run()
110                 if err != nil {
111                         return 1
112                 }
113         }
114
115         if inst.EatMyData {
116                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends", "eatmydata")
117                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
118                 cmd.Stdout = stdout
119                 cmd.Stderr = stderr
120                 err = cmd.Run()
121                 if err != nil {
122                         return 1
123                 }
124         }
125
126         pkgs := prodpkgs(osv)
127
128         if pkg {
129                 pkgs = append(pkgs,
130                         "dpkg-dev",
131                         "eatmydata", // install it for later steps, even if we're not using it now
132                         "rsync",
133                 )
134         }
135
136         if dev || test || pkg {
137                 pkgs = append(pkgs,
138                         "automake",
139                         "bison",
140                         "bsdmainutils",
141                         "build-essential",
142                         "cadaver",
143                         "curl",
144                         "cython3",
145                         "default-jdk-headless",
146                         "default-jre-headless",
147                         "gettext",
148                         "iceweasel",
149                         "libattr1-dev",
150                         "libcrypt-ssleay-perl",
151                         "libfuse-dev",
152                         "libgnutls28-dev",
153                         "libjson-perl",
154                         "libpam-dev",
155                         "libpcre3-dev",
156                         "libpq-dev",
157                         "libreadline-dev",
158                         "libssl-dev",
159                         "libwww-perl",
160                         "libxml2-dev",
161                         "libxslt1-dev",
162                         "linkchecker",
163                         "lsof",
164                         "make",
165                         "net-tools",
166                         "pandoc",
167                         "perl-modules",
168                         "pkg-config",
169                         "postgresql",
170                         "postgresql-contrib",
171                         "python3-dev",
172                         "python3-venv",
173                         "python3-virtualenv",
174                         "r-base",
175                         "r-cran-testthat",
176                         "r-cran-devtools",
177                         "r-cran-knitr",
178                         "r-cran-markdown",
179                         "r-cran-roxygen2",
180                         "r-cran-xml",
181                         "sudo",
182                         "uuid-dev",
183                         "wget",
184                         "xvfb",
185                 )
186                 if dev || test {
187                         pkgs = append(pkgs,
188                                 "squashfs-tools", // for singularity
189                         )
190                 }
191                 switch {
192                 case osv.Debian && osv.Major >= 10:
193                         pkgs = append(pkgs, "libcurl4")
194                 default:
195                         pkgs = append(pkgs, "libcurl3")
196                 }
197                 cmd := exec.CommandContext(ctx, "apt-get")
198                 if inst.EatMyData {
199                         cmd = exec.CommandContext(ctx, "eatmydata", "apt-get")
200                 }
201                 cmd.Args = append(cmd.Args, "install", "--yes", "--no-install-recommends")
202                 cmd.Args = append(cmd.Args, pkgs...)
203                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
204                 cmd.Stdout = stdout
205                 cmd.Stderr = stderr
206                 err = cmd.Run()
207                 if err != nil {
208                         return 1
209                 }
210         }
211
212         os.Mkdir("/var/lib/arvados", 0755)
213         os.Mkdir("/var/lib/arvados/tmp", 0700)
214         if prod || pkg {
215                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
216                 u, er := user.Lookup("www-data")
217                 if er != nil {
218                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
219                         return 1
220                 }
221                 uid, _ := strconv.Atoi(u.Uid)
222                 gid, _ := strconv.Atoi(u.Gid)
223                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
224                 if err != nil {
225                         return 1
226                 }
227         }
228         rubyversion := "2.7.2"
229         rubymajorversion := rubyversion[:strings.LastIndex(rubyversion, ".")]
230         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+rubyversion)) {
231                 logger.Print("ruby " + rubyversion + " already installed")
232         } else {
233                 err = inst.runBash(`
234 tmp="$(mktemp -d)"
235 trap 'rm -r "${tmp}"' ERR EXIT
236 wget --progress=dot:giga -O- https://cache.ruby-lang.org/pub/ruby/`+rubymajorversion+`/ruby-`+rubyversion+`.tar.gz | tar -C "${tmp}" -xzf -
237 cd "${tmp}/ruby-`+rubyversion+`"
238 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
239 make -j8
240 make install
241 /var/lib/arvados/bin/gem install bundler --no-document
242 `, stdout, stderr)
243                 if err != nil {
244                         return 1
245                 }
246         }
247
248         if !prod {
249                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
250                         logger.Print("go " + goversion + " already installed")
251                 } else {
252                         err = inst.runBash(`
253 cd /tmp
254 rm -rf /var/lib/arvados/go/
255 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
256 ln -sf /var/lib/arvados/go/bin/* /usr/local/bin/
257 `, stdout, stderr)
258                         if err != nil {
259                                 return 1
260                         }
261                 }
262         }
263
264         if !prod && !pkg {
265                 pjsversion := "1.9.8"
266                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
267                         logger.Print("phantomjs " + pjsversion + " already installed")
268                 } else {
269                         err = inst.runBash(`
270 PJS=phantomjs-`+pjsversion+`-linux-x86_64
271 wget --progress=dot:giga -O- https://bitbucket.org/ariya/phantomjs/downloads/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
272 ln -sf /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
273 `, stdout, stderr)
274                         if err != nil {
275                                 return 1
276                         }
277                 }
278
279                 geckoversion := "0.24.0"
280                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
281                         logger.Print("geckodriver " + geckoversion + " already installed")
282                 } else {
283                         err = inst.runBash(`
284 GD=v`+geckoversion+`
285 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
286 ln -sf /var/lib/arvados/bin/geckodriver /usr/local/bin/
287 `, stdout, stderr)
288                         if err != nil {
289                                 return 1
290                         }
291                 }
292
293                 nodejsversion := "v12.22.2"
294                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == nodejsversion+"\n" {
295                         logger.Print("nodejs " + nodejsversion + " already installed")
296                 } else {
297                         err = inst.runBash(`
298 NJS=`+nodejsversion+`
299 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
300 ln -sf /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
301 `, stdout, stderr)
302                         if err != nil {
303                                 return 1
304                         }
305                 }
306
307                 gradleversion := "5.3.1"
308                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
309                         logger.Print("gradle " + gradleversion + " already installed")
310                 } else {
311                         err = inst.runBash(`
312 G=`+gradleversion+`
313 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
314 trap "rm ${zip}" ERR
315 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
316 unzip -o -d /var/lib/arvados ${zip}
317 ln -sf /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
318 rm ${zip}
319 `, stdout, stderr)
320                         if err != nil {
321                                 return 1
322                         }
323                 }
324
325                 singularityversion := "3.7.4"
326                 if havesingularityversion, err := exec.Command("/var/lib/arvados/bin/singularity", "--version").CombinedOutput(); err == nil && strings.Contains(string(havesingularityversion), singularityversion) {
327                         logger.Print("singularity " + singularityversion + " already installed")
328                 } else if dev || test {
329                         err = inst.runBash(`
330 S=`+singularityversion+`
331 tmp=/var/lib/arvados/tmp/singularity
332 trap "rm -r ${tmp}" ERR EXIT
333 cd /var/lib/arvados/tmp
334 git clone https://github.com/sylabs/singularity
335 cd singularity
336 git checkout v${S}
337 ./mconfig --prefix=/var/lib/arvados
338 make -C ./builddir
339 make -C ./builddir install
340 `, stdout, stderr)
341                         if err != nil {
342                                 return 1
343                         }
344                 }
345
346                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
347                 // it's installed, locale -a reports it as
348                 // "en_US.utf8".
349                 wantlocale := "en_US.UTF-8"
350                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
351                         logger.Print("locale " + wantlocale + " already installed")
352                 } else {
353                         err = inst.runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
354                         if err != nil {
355                                 return 1
356                         }
357                 }
358
359                 var pgc struct {
360                         Version       string
361                         Cluster       string
362                         Port          int
363                         Status        string
364                         Owner         string
365                         DataDirectory string
366                         LogFile       string
367                 }
368                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
369                         err = fmt.Errorf("pg_lsclusters: %s", err2)
370                         return 1
371                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
372                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
373                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
374                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
375                         return 1
376                 } else if pgc.Status == "online" {
377                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
378                 } else {
379                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
380                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
381                         cmd.Stdout = stdout
382                         cmd.Stderr = stderr
383                         err = cmd.Start()
384                         if err != nil {
385                                 return 1
386                         }
387                         defer func() {
388                                 cmd.Process.Signal(syscall.SIGTERM)
389                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
390                                 cmd.Wait()
391                         }()
392                         err = waitPostgreSQLReady()
393                         if err != nil {
394                                 return 1
395                         }
396                 }
397
398                 if os.Getpid() == 1 {
399                         // We are the init process (presumably in a
400                         // docker container) so although postgresql is
401                         // installed, it's not running, and initdb
402                         // might never have been run.
403                 }
404
405                 var needcoll []string
406                 // If the en_US.UTF-8 locale wasn't installed when
407                 // postgresql initdb ran, it needs to be added
408                 // explicitly before we can use it in our test suite.
409                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
410                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
411                         cmd.Dir = "/"
412                         out, err2 := cmd.CombinedOutput()
413                         if err != nil {
414                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
415                                 return 1
416                         }
417                         if strings.Contains(string(out), "1") {
418                                 logger.Infof("postgresql supports collation %s", collname)
419                         } else {
420                                 needcoll = append(needcoll, collname)
421                         }
422                 }
423                 if len(needcoll) > 0 && os.Getpid() != 1 {
424                         // In order for the CREATE COLLATION statement
425                         // below to work, the locale must have existed
426                         // when PostgreSQL started up. If we're
427                         // running as init, we must have started
428                         // PostgreSQL ourselves after installing the
429                         // locales. Otherwise, it might need a
430                         // restart, so we attempt to restart it with
431                         // systemd.
432                         if err = inst.runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
433                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
434                         } else if err = waitPostgreSQLReady(); err != nil {
435                                 return 1
436                         }
437                 }
438                 for _, collname := range needcoll {
439                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
440                         cmd.Stdout = stdout
441                         cmd.Stderr = stderr
442                         cmd.Dir = "/"
443                         err = cmd.Run()
444                         if err != nil {
445                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
446                                 return 1
447                         }
448                 }
449
450                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
451                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
452                 cmd.Dir = "/"
453                 if err := cmd.Run(); err == nil {
454                         logger.Print("arvados role exists; superuser privileges added, password updated")
455                 } else {
456                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
457                         cmd.Dir = "/"
458                         cmd.Stdout = stdout
459                         cmd.Stderr = stderr
460                         err = cmd.Run()
461                         if err != nil {
462                                 return 1
463                         }
464                 }
465         }
466
467         if prod || pkg {
468                 // Install Rails apps to /var/lib/arvados/{railsapi,workbench1}/
469                 for dstdir, srcdir := range map[string]string{
470                         "railsapi":   "services/api",
471                         "workbench1": "apps/workbench",
472                 } {
473                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
474                         cmd := exec.Command("rsync",
475                                 "-a", "--no-owner", "--no-group", "--delete-after", "--delete-excluded",
476                                 "--exclude", "/coverage",
477                                 "--exclude", "/log",
478                                 "--exclude", "/tmp",
479                                 "--exclude", "/vendor",
480                                 "--exclude", "/config/environments",
481                                 "./", "/var/lib/arvados/"+dstdir+"/")
482                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
483                         cmd.Stdout = stdout
484                         cmd.Stderr = stderr
485                         err = cmd.Run()
486                         if err != nil {
487                                 return 1
488                         }
489                         for _, cmdline := range [][]string{
490                                 {"mkdir", "-p", "log", "tmp", ".bundle", "/var/www/.gem", "/var/www/.bundle", "/var/www/.passenger"},
491                                 {"touch", "log/production.log"},
492                                 {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.gem", "/var/www/.bundle", "/var/www/.passenger", "log", "tmp", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
493                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:2.2.19"},
494                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--deployment", "--jobs", "8", "--path", "/var/www/.gem"},
495                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
496                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
497                         } {
498                                 cmd = exec.Command(cmdline[0], cmdline[1:]...)
499                                 cmd.Dir = "/var/lib/arvados/" + dstdir
500                                 cmd.Stdout = stdout
501                                 cmd.Stderr = stderr
502                                 fmt.Fprintf(stderr, "... %s\n", cmd.Args)
503                                 err = cmd.Run()
504                                 if err != nil {
505                                         return 1
506                                 }
507                         }
508                         cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
509                         cmd.Dir = "/var/lib/arvados/" + dstdir
510                         cmd.Stdout = stdout
511                         cmd.Stderr = stderr
512                         err = cmd.Run()
513                         if err != nil && !strings.Contains(err.Error(), "exit status 2") {
514                                 // Exit code 2 indicates there were warnings (like
515                                 // "other passenger installations have been detected",
516                                 // which we can't expect to avoid) but no errors.
517                                 // Other non-zero exit codes (1, 9) indicate errors.
518                                 return 1
519                         }
520                 }
521
522                 // Install Go programs to /var/lib/arvados/bin/
523                 for _, srcdir := range []string{
524                         "cmd/arvados-client",
525                         "cmd/arvados-server",
526                         "services/arv-git-httpd",
527                         "services/crunch-dispatch-local",
528                         "services/crunch-dispatch-slurm",
529                         "services/health",
530                         "services/keep-balance",
531                         "services/keep-web",
532                         "services/keepproxy",
533                         "services/keepstore",
534                         "services/ws",
535                 } {
536                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
537                         cmd := exec.Command("go", "install", "-ldflags", "-X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+" -X main.version="+inst.PackageVersion)
538                         cmd.Env = append(cmd.Env, os.Environ()...)
539                         cmd.Env = append(cmd.Env, "GOBIN=/var/lib/arvados/bin")
540                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
541                         cmd.Stdout = stdout
542                         cmd.Stderr = stderr
543                         err = cmd.Run()
544                         if err != nil {
545                                 return 1
546                         }
547                 }
548
549                 // Copy assets from source tree to /var/lib/arvados/share
550                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
551                 cmd.Stdout = stdout
552                 cmd.Stderr = stderr
553                 err = cmd.Run()
554                 if err != nil {
555                         return 1
556                 }
557         }
558
559         return 0
560 }
561
562 type osversion struct {
563         Debian bool
564         Ubuntu bool
565         Centos bool
566         Major  int
567 }
568
569 func identifyOS() (osversion, error) {
570         var osv osversion
571         f, err := os.Open("/etc/os-release")
572         if err != nil {
573                 return osv, err
574         }
575         defer f.Close()
576
577         kv := map[string]string{}
578         scanner := bufio.NewScanner(f)
579         for scanner.Scan() {
580                 line := strings.TrimSpace(scanner.Text())
581                 if strings.HasPrefix(line, "#") {
582                         continue
583                 }
584                 toks := strings.SplitN(line, "=", 2)
585                 if len(toks) != 2 {
586                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
587                 }
588                 k := toks[0]
589                 v := strings.Trim(toks[1], `"`)
590                 if v == toks[1] {
591                         v = strings.Trim(v, `'`)
592                 }
593                 kv[k] = v
594         }
595         if err = scanner.Err(); err != nil {
596                 return osv, err
597         }
598         switch kv["ID"] {
599         case "ubuntu":
600                 osv.Ubuntu = true
601         case "debian":
602                 osv.Debian = true
603         case "centos":
604                 osv.Centos = true
605         default:
606                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
607         }
608         vstr := kv["VERSION_ID"]
609         if i := strings.Index(vstr, "."); i > 0 {
610                 vstr = vstr[:i]
611         }
612         osv.Major, err = strconv.Atoi(vstr)
613         if err != nil {
614                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
615         }
616         return osv, nil
617 }
618
619 func waitPostgreSQLReady() error {
620         for deadline := time.Now().Add(10 * time.Second); ; {
621                 output, err := exec.Command("pg_isready").CombinedOutput()
622                 if err == nil {
623                         return nil
624                 } else if time.Now().After(deadline) {
625                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
626                 } else {
627                         time.Sleep(time.Second)
628                 }
629         }
630 }
631
632 func (inst *installCommand) runBash(script string, stdout, stderr io.Writer) error {
633         cmd := exec.Command("bash", "-")
634         if inst.EatMyData {
635                 cmd = exec.Command("eatmydata", "bash", "-")
636         }
637         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
638         cmd.Stdout = stdout
639         cmd.Stderr = stderr
640         return cmd.Run()
641 }
642
643 func prodpkgs(osv osversion) []string {
644         pkgs := []string{
645                 "ca-certificates",
646                 "curl",
647                 "fuse",
648                 "git",
649                 "gitolite3",
650                 "graphviz",
651                 "haveged",
652                 "libcurl3-gnutls",
653                 "libxslt1.1",
654                 "nginx",
655                 "python",
656                 "sudo",
657         }
658         if osv.Debian || osv.Ubuntu {
659                 if osv.Debian && osv.Major == 8 {
660                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
661                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
662                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
663                 }
664                 return append(pkgs,
665                         "g++",
666                         "libcurl4-openssl-dev", // services/api
667                         "libpq-dev",
668                         "libpython2.7", // services/fuse
669                         "mime-support", // keep-web
670                         "zlib1g-dev",   // services/api
671                 )
672         } else if osv.Centos {
673                 return append(pkgs,
674                         "fuse-libs", // services/fuse
675                         "gcc",
676                         "gcc-c++",
677                         "libcurl-devel",    // services/api
678                         "mailcap",          // keep-web
679                         "postgresql-devel", // services/api
680                 )
681         } else {
682                 panic("os version not supported")
683         }
684 }
685
686 func ProductionDependencies() ([]string, error) {
687         osv, err := identifyOS()
688         if err != nil {
689                 return nil, err
690         }
691         return prodpkgs(osv), nil
692 }