Merge branch '21030-update-perm-cte' refs #21030
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         _ "embed"
12         "errors"
13         "flag"
14         "fmt"
15         "io"
16         "os"
17         "os/exec"
18         "os/user"
19         "path/filepath"
20         "runtime"
21         "strconv"
22         "strings"
23         "syscall"
24         "time"
25
26         "git.arvados.org/arvados.git/lib/cmd"
27         "git.arvados.org/arvados.git/sdk/go/ctxlog"
28         "github.com/lib/pq"
29 )
30
31 var Command cmd.Handler = &installCommand{}
32
33 const goversion = "1.20.6"
34
35 const (
36         rubyversion             = "2.7.7"
37         bundlerversion          = "2.2.19"
38         singularityversion      = "3.10.4"
39         pjsversion              = "1.9.8"
40         geckoversion            = "0.24.0"
41         gradleversion           = "5.3.1"
42         nodejsversion           = "v12.22.12"
43         devtestDatabasePassword = "insecure_arvados_test"
44 )
45
46 //go:embed arvados.service
47 var arvadosServiceFile []byte
48
49 type installCommand struct {
50         ClusterType    string
51         SourcePath     string
52         PackageVersion string
53         EatMyData      bool
54 }
55
56 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
57         logger := ctxlog.New(stderr, "text", "info")
58         ctx := ctxlog.Context(context.Background(), logger)
59         ctx, cancel := context.WithCancel(ctx)
60         defer cancel()
61
62         var err error
63         defer func() {
64                 if err != nil {
65                         logger.WithError(err).Info("exiting")
66                 }
67         }()
68
69         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
70         flags.SetOutput(stderr)
71         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
72         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
73         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
74         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
75         flags.BoolVar(&inst.EatMyData, "eatmydata", false, "use eatmydata to speed up install")
76
77         if ok, code := cmd.ParseFlags(flags, prog, args, "", stderr); !ok {
78                 return code
79         } else if *versionFlag {
80                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
81         }
82
83         var dev, test, prod, pkg bool
84         switch inst.ClusterType {
85         case "development":
86                 dev = true
87         case "test":
88                 test = true
89         case "production":
90                 prod = true
91         case "package":
92                 pkg = true
93         default:
94                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
95                 return 2
96         }
97
98         if prod {
99                 err = errors.New("production install is not yet implemented")
100                 return 1
101         }
102
103         osv, err := identifyOS()
104         if err != nil {
105                 return 1
106         }
107
108         listdir, err := os.Open("/var/lib/apt/lists")
109         if err != nil {
110                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
111         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
112                 // Special case for a base docker image where the
113                 // package cache has been deleted and all "apt-get
114                 // install" commands will fail unless we fetch repos.
115                 cmd := exec.CommandContext(ctx, "apt-get", "update")
116                 cmd.Stdout = stdout
117                 cmd.Stderr = stderr
118                 err = cmd.Run()
119                 if err != nil {
120                         return 1
121                 }
122         }
123
124         if inst.EatMyData {
125                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends", "eatmydata")
126                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
127                 cmd.Stdout = stdout
128                 cmd.Stderr = stderr
129                 err = cmd.Run()
130                 if err != nil {
131                         return 1
132                 }
133         }
134
135         pkgs := prodpkgs(osv)
136
137         if pkg {
138                 pkgs = append(pkgs,
139                         "dpkg-dev",
140                         "eatmydata", // install it for later steps, even if we're not using it now
141                 )
142         }
143
144         if dev || test || pkg {
145                 pkgs = append(pkgs,
146                         "automake",
147                         "bison",
148                         "bsdmainutils",
149                         "build-essential",
150                         "cadaver",
151                         "curl",
152                         "cython3",
153                         "default-jdk-headless",
154                         "default-jre-headless",
155                         "gettext",
156                         "libattr1-dev",
157                         "libfuse-dev",
158                         "libgbm1", // cypress / workbench2 tests
159                         "libgnutls28-dev",
160                         "libpam-dev",
161                         "libpcre3-dev",
162                         "libpq-dev",
163                         "libreadline-dev",
164                         "libssl-dev",
165                         "libxml2-dev",
166                         "libxslt1-dev",
167                         "linkchecker",
168                         "lsof",
169                         "make",
170                         "net-tools",
171                         "pandoc",
172                         "pkg-config",
173                         "postgresql",
174                         "postgresql-contrib",
175                         "python3-dev",
176                         "python3-venv",
177                         "python3-virtualenv",
178                         "r-base",
179                         "r-cran-testthat",
180                         "r-cran-devtools",
181                         "r-cran-knitr",
182                         "r-cran-markdown",
183                         "r-cran-roxygen2",
184                         "r-cran-xml",
185                         "rsync",
186                         "sudo",
187                         "uuid-dev",
188                         "wget",
189                         "xvfb",
190                         "zlib1g-dev", // services/api
191                 )
192                 if test {
193                         if osv.Debian && osv.Major <= 10 {
194                                 pkgs = append(pkgs, "iceweasel")
195                         } else if osv.Debian && osv.Major >= 11 {
196                                 pkgs = append(pkgs, "firefox-esr")
197                         } else {
198                                 pkgs = append(pkgs, "firefox")
199                         }
200                 }
201                 if dev || test {
202                         pkgs = append(pkgs,
203                                 "libglib2.0-dev", // singularity (conmon)
204                                 "libseccomp-dev", // singularity (seccomp)
205                                 "squashfs-tools", // singularity
206                                 "gnupg")          // docker install recipe
207                 }
208                 switch {
209                 case osv.Debian && osv.Major >= 11:
210                         pkgs = append(pkgs, "g++", "libcurl4", "libcurl4-openssl-dev")
211                 case osv.Debian && osv.Major >= 10:
212                         pkgs = append(pkgs, "g++", "libcurl4", "libcurl4-openssl-dev")
213                 case osv.Debian || osv.Ubuntu:
214                         pkgs = append(pkgs, "g++", "libcurl3", "libcurl3-openssl-dev")
215                 case osv.Centos:
216                         pkgs = append(pkgs, "gcc", "gcc-c++", "libcurl-devel", "postgresql-devel")
217                 }
218                 cmd := exec.CommandContext(ctx, "apt-get")
219                 if inst.EatMyData {
220                         cmd = exec.CommandContext(ctx, "eatmydata", "apt-get")
221                 }
222                 cmd.Args = append(cmd.Args, "install", "--yes", "--no-install-recommends")
223                 cmd.Args = append(cmd.Args, pkgs...)
224                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
225                 cmd.Stdout = stdout
226                 cmd.Stderr = stderr
227                 err = cmd.Run()
228                 if err != nil {
229                         return 1
230                 }
231         }
232
233         if dev || test {
234                 if havedockerversion, err2 := exec.Command("docker", "--version").CombinedOutput(); err2 == nil {
235                         logger.Printf("%s installed, assuming that version is ok", bytes.TrimSuffix(havedockerversion, []byte("\n")))
236                 } else if osv.Debian {
237                         var codename string
238                         switch osv.Major {
239                         case 10:
240                                 codename = "buster"
241                         case 11:
242                                 codename = "bullseye"
243                         case 12:
244                                 codename = "bookworm"
245                         default:
246                                 err = fmt.Errorf("don't know how to install docker-ce for debian %d", osv.Major)
247                                 return 1
248                         }
249                         err = inst.runBash(`
250 rm -f /usr/share/keyrings/docker-archive-keyring.gpg
251 curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
252 echo 'deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian/ `+codename+` stable' | \
253     tee /etc/apt/sources.list.d/docker.list
254 apt-get update
255 DEBIAN_FRONTEND=noninteractive apt-get --yes --no-install-recommends install docker-ce
256 `, stdout, stderr)
257                         if err != nil {
258                                 return 1
259                         }
260                 } else {
261                         err = fmt.Errorf("don't know how to install docker for osversion %v", osv)
262                         return 1
263                 }
264
265                 err = inst.runBash(`
266 key=fs.inotify.max_user_watches
267 min=524288
268 if [[ "$(sysctl --values "${key}")" -lt "${min}" ]]; then
269     sysctl "${key}=${min}"
270     # writing sysctl worked, so we should make it permanent
271     echo "${key}=${min}" | tee -a /etc/sysctl.conf
272     sysctl -p
273 fi
274 `, stdout, stderr)
275                 if err != nil {
276                         err = fmt.Errorf("couldn't set fs.inotify.max_user_watches value. (Is this a docker container? Fix this on the docker host by adding fs.inotify.max_user_watches=524288 to /etc/sysctl.conf and running `sysctl -p`)")
277                         return 1
278                 }
279         }
280
281         os.Mkdir("/var/lib/arvados", 0755)
282         os.Mkdir("/var/lib/arvados/tmp", 0700)
283         if prod || pkg {
284                 u, er := user.Lookup("www-data")
285                 if er != nil {
286                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
287                         return 1
288                 }
289                 uid, _ := strconv.Atoi(u.Uid)
290                 gid, _ := strconv.Atoi(u.Gid)
291                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
292                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
293                 if err != nil {
294                         return 1
295                 }
296         }
297         rubymajorversion := rubyversion[:strings.LastIndex(rubyversion, ".")]
298         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+rubyversion)) {
299                 logger.Print("ruby " + rubyversion + " already installed")
300         } else {
301                 err = inst.runBash(`
302 tmp="$(mktemp -d)"
303 trap 'rm -r "${tmp}"' ERR EXIT
304 wget --progress=dot:giga -O- https://cache.ruby-lang.org/pub/ruby/`+rubymajorversion+`/ruby-`+rubyversion+`.tar.gz | tar -C "${tmp}" -xzf -
305 cd "${tmp}/ruby-`+rubyversion+`"
306 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
307 make -j8
308 make install
309 /var/lib/arvados/bin/gem install bundler --no-document
310 `, stdout, stderr)
311                 if err != nil {
312                         return 1
313                 }
314         }
315
316         if !prod {
317                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
318                         logger.Print("go " + goversion + " already installed")
319                 } else {
320                         err = inst.runBash(`
321 cd /tmp
322 rm -rf /var/lib/arvados/go/
323 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
324 ln -sfv /var/lib/arvados/go/bin/* /usr/local/bin/
325 `, stdout, stderr)
326                         if err != nil {
327                                 return 1
328                         }
329                 }
330         }
331
332         if !prod && !pkg {
333                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
334                         logger.Print("phantomjs " + pjsversion + " already installed")
335                 } else {
336                         err = inst.runBash(`
337 PJS=phantomjs-`+pjsversion+`-linux-x86_64
338 wget --progress=dot:giga -O- https://cache.arvados.org/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
339 ln -sfv /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
340 `, stdout, stderr)
341                         if err != nil {
342                                 return 1
343                         }
344                 }
345
346                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
347                         logger.Print("geckodriver " + geckoversion + " already installed")
348                 } else {
349                         err = inst.runBash(`
350 GD=v`+geckoversion+`
351 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
352 ln -sfv /var/lib/arvados/bin/geckodriver /usr/local/bin/
353 `, stdout, stderr)
354                         if err != nil {
355                                 return 1
356                         }
357                 }
358
359                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
360                         logger.Print("gradle " + gradleversion + " already installed")
361                 } else {
362                         err = inst.runBash(`
363 G=`+gradleversion+`
364 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
365 trap "rm ${zip}" ERR
366 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
367 unzip -o -d /var/lib/arvados ${zip}
368 ln -sfv /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
369 rm ${zip}
370 `, stdout, stderr)
371                         if err != nil {
372                                 return 1
373                         }
374                 }
375
376                 if havesingularityversion, err := exec.Command("/var/lib/arvados/bin/singularity", "--version").CombinedOutput(); err == nil && strings.Contains(string(havesingularityversion), singularityversion) {
377                         logger.Print("singularity " + singularityversion + " already installed")
378                 } else if dev || test {
379                         err = inst.runBash(`
380 S=`+singularityversion+`
381 tmp=/var/lib/arvados/tmp/singularity
382 trap "rm -r ${tmp}" ERR EXIT
383 cd /var/lib/arvados/tmp
384 git clone --recurse-submodules https://github.com/sylabs/singularity
385 cd singularity
386 git checkout v${S}
387 ./mconfig --prefix=/var/lib/arvados
388 make -C ./builddir
389 make -C ./builddir install
390 `, stdout, stderr)
391                         if err != nil {
392                                 return 1
393                         }
394                 }
395
396                 err = inst.runBash(`
397 install /usr/bin/nsenter /var/lib/arvados/bin/nsenter
398 setcap "cap_sys_admin+pei cap_sys_chroot+pei" /var/lib/arvados/bin/nsenter
399 `, stdout, stderr)
400                 if err != nil {
401                         return 1
402                 }
403
404                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
405                 // it's installed, locale -a reports it as
406                 // "en_US.utf8".
407                 wantlocale := "en_US.UTF-8"
408                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
409                         logger.Print("locale " + wantlocale + " already installed")
410                 } else {
411                         err = inst.runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
412                         if err != nil {
413                                 return 1
414                         }
415                 }
416
417                 var pgc struct {
418                         Version       string
419                         Cluster       string
420                         Port          int
421                         Status        string
422                         Owner         string
423                         DataDirectory string
424                         LogFile       string
425                 }
426                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
427                         err = fmt.Errorf("pg_lsclusters: %s", err2)
428                         return 1
429                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
430                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
431                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
432                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
433                         return 1
434                 } else if pgc.Status == "online" {
435                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
436                 } else {
437                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
438                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
439                         cmd.Stdout = stdout
440                         cmd.Stderr = stderr
441                         err = cmd.Start()
442                         if err != nil {
443                                 return 1
444                         }
445                         defer func() {
446                                 cmd.Process.Signal(syscall.SIGTERM)
447                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
448                                 cmd.Wait()
449                         }()
450                         err = waitPostgreSQLReady()
451                         if err != nil {
452                                 return 1
453                         }
454                 }
455
456                 if os.Getpid() == 1 {
457                         // We are the init process (presumably in a
458                         // docker container) so although postgresql is
459                         // installed, it's not running, and initdb
460                         // might never have been run.
461                 }
462
463                 var needcoll []string
464                 // If the en_US.UTF-8 locale wasn't installed when
465                 // postgresql initdb ran, it needs to be added
466                 // explicitly before we can use it in our test suite.
467                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
468                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
469                         cmd.Dir = "/"
470                         out, err2 := cmd.CombinedOutput()
471                         if err != nil {
472                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
473                                 return 1
474                         }
475                         if strings.Contains(string(out), "1") {
476                                 logger.Infof("postgresql supports collation %s", collname)
477                         } else {
478                                 needcoll = append(needcoll, collname)
479                         }
480                 }
481                 if len(needcoll) > 0 && os.Getpid() != 1 {
482                         // In order for the CREATE COLLATION statement
483                         // below to work, the locale must have existed
484                         // when PostgreSQL started up. If we're
485                         // running as init, we must have started
486                         // PostgreSQL ourselves after installing the
487                         // locales. Otherwise, it might need a
488                         // restart, so we attempt to restart it with
489                         // systemd.
490                         if err = inst.runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
491                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
492                         } else if err = waitPostgreSQLReady(); err != nil {
493                                 return 1
494                         }
495                 }
496                 for _, collname := range needcoll {
497                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
498                         cmd.Stdout = stdout
499                         cmd.Stderr = stderr
500                         cmd.Dir = "/"
501                         err = cmd.Run()
502                         if err != nil {
503                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
504                                 return 1
505                         }
506                 }
507
508                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
509                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
510                 cmd.Dir = "/"
511                 if err := cmd.Run(); err == nil {
512                         logger.Print("arvados role exists; superuser privileges added, password updated")
513                 } else {
514                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
515                         cmd.Dir = "/"
516                         cmd.Stdout = stdout
517                         cmd.Stderr = stderr
518                         err = cmd.Run()
519                         if err != nil {
520                                 return 1
521                         }
522                 }
523         }
524
525         if !prod {
526                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == nodejsversion+"\n" {
527                         logger.Print("nodejs " + nodejsversion + " already installed")
528                 } else {
529                         err = inst.runBash(`
530 NJS=`+nodejsversion+`
531 rm -rf /var/lib/arvados/node-*-linux-x64
532 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
533 ln -sfv /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
534 `, stdout, stderr)
535                         if err != nil {
536                                 return 1
537                         }
538                 }
539
540                 if haveyarnversion, err := exec.Command("/usr/local/bin/yarn", "--version").CombinedOutput(); err == nil && len(haveyarnversion) > 0 {
541                         logger.Print("yarn " + strings.TrimSpace(string(haveyarnversion)) + " already installed")
542                 } else {
543                         err = inst.runBash(`
544 npm install -g yarn
545 ln -sfv /var/lib/arvados/node-`+nodejsversion+`-linux-x64/bin/{yarn,yarnpkg} /usr/local/bin/
546 `, stdout, stderr)
547                         if err != nil {
548                                 return 1
549                         }
550                 }
551         }
552
553         if prod || pkg {
554                 // Install Go programs to /var/lib/arvados/bin/
555                 for _, srcdir := range []string{
556                         "cmd/arvados-client",
557                         "cmd/arvados-server",
558                 } {
559                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
560                         cmd := exec.Command("go", "install", "-ldflags", "-X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+" -X main.version="+inst.PackageVersion+" -s -w")
561                         cmd.Env = append(cmd.Env, os.Environ()...)
562                         cmd.Env = append(cmd.Env, "GOBIN=/var/lib/arvados/bin")
563                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
564                         cmd.Stdout = stdout
565                         cmd.Stderr = stderr
566                         err = cmd.Run()
567                         if err != nil {
568                                 return 1
569                         }
570                 }
571
572                 // Copy assets from source tree to /var/lib/arvados/share
573                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
574                 cmd.Stdout = stdout
575                 cmd.Stderr = stderr
576                 err = cmd.Run()
577                 if err != nil {
578                         return 1
579                 }
580
581                 // Install python SDK and arv-mount in
582                 // /var/lib/arvados/lib/python.
583                 //
584                 // setup.py writes a file in the source directory in
585                 // order to include the version number in the package
586                 // itself.  We don't want to write to the source tree
587                 // (in "arvados-package" context it's mounted
588                 // readonly) so we run setup.py in a temporary copy of
589                 // the source dir.
590                 if err = inst.runBash(`
591 v=/var/lib/arvados/lib/python
592 tmp=/var/lib/arvados/tmp/python
593 python3 -m venv "$v"
594 . "$v/bin/activate"
595 pip3 install --no-cache-dir 'setuptools>=18.5' 'pip>=7'
596 export ARVADOS_BUILDING_VERSION="`+inst.PackageVersion+`"
597 for src in "`+inst.SourcePath+`/sdk/python" "`+inst.SourcePath+`/services/fuse"; do
598   rsync -a --delete-after "$src/" "$tmp/"
599   cd "$tmp"
600   python3 setup.py install
601   cd ..
602   rm -rf "$tmp"
603 done
604 `, stdout, stderr); err != nil {
605                         return 1
606                 }
607
608                 // Install Rails apps to /var/lib/arvados/{railsapi,workbench1}/
609                 for dstdir, srcdir := range map[string]string{
610                         "railsapi":   "services/api",
611                         "workbench1": "apps/workbench",
612                 } {
613                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
614                         cmd := exec.Command("rsync",
615                                 "-a", "--no-owner", "--no-group", "--delete-after", "--delete-excluded",
616                                 "--exclude", "/coverage",
617                                 "--exclude", "/log",
618                                 "--exclude", "/node_modules",
619                                 "--exclude", "/tmp",
620                                 "--exclude", "/public/assets",
621                                 "--exclude", "/vendor",
622                                 "--exclude", "/config/environments",
623                                 "./", "/var/lib/arvados/"+dstdir+"/")
624                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
625                         cmd.Stdout = stdout
626                         cmd.Stderr = stderr
627                         err = cmd.Run()
628                         if err != nil {
629                                 return 1
630                         }
631                         for _, cmdline := range [][]string{
632                                 {"mkdir", "-p", "log", "public/assets", "tmp", "vendor", ".bundle", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger"},
633                                 {"touch", "log/production.log"},
634                                 {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger", "log", "tmp", "vendor", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
635                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:" + bundlerversion},
636                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "deployment", "true"},
637                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "path", "/var/www/.gem"},
638                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "without", "development test diagnostics performance"},
639                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--jobs", fmt.Sprintf("%d", runtime.NumCPU())},
640
641                                 {"chown", "www-data:www-data", ".", "public/assets"},
642                                 // {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "system", "true"},
643                                 {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "npm:install"},
644                                 {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "assets:precompile"},
645                                 {"chown", "root:root", "."},
646                                 {"chown", "-R", "root:root", "public/assets", "vendor"},
647
648                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
649                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
650                         } {
651                                 if cmdline[len(cmdline)-2] == "rake" && dstdir != "workbench1" {
652                                         continue
653                                 }
654                                 cmd = exec.Command(cmdline[0], cmdline[1:]...)
655                                 cmd.Dir = "/var/lib/arvados/" + dstdir
656                                 cmd.Stdout = stdout
657                                 cmd.Stderr = stderr
658                                 fmt.Fprintf(stderr, "... %s\n", cmd.Args)
659                                 err = cmd.Run()
660                                 if err != nil {
661                                         return 1
662                                 }
663                         }
664                         cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
665                         cmd.Dir = "/var/lib/arvados/" + dstdir
666                         cmd.Stdout = stdout
667                         cmd.Stderr = stderr
668                         err = cmd.Run()
669                         if err != nil && !strings.Contains(err.Error(), "exit status 2") {
670                                 // Exit code 2 indicates there were warnings (like
671                                 // "other passenger installations have been detected",
672                                 // which we can't expect to avoid) but no errors.
673                                 // Other non-zero exit codes (1, 9) indicate errors.
674                                 return 1
675                         }
676                 }
677
678                 // Install workbench2 app to /var/lib/arvados/workbench2/
679                 if err = inst.runBash(`
680 cd `+inst.SourcePath+`/services/workbench2
681 VERSION="`+inst.PackageVersion+`" BUILD_NUMBER=1 GIT_COMMIT=000000000 yarn build
682 rsync -a --delete-after build/ /var/lib/arvados/workbench2/
683 `, stdout, stderr); err != nil {
684                         return 1
685                 }
686
687                 // Install arvados-cli gem (binaries go in
688                 // /var/lib/arvados/bin)
689                 if err = inst.runBash(`
690 /var/lib/arvados/bin/gem install --conservative --no-document arvados-cli
691 `, stdout, stderr); err != nil {
692                         return 1
693                 }
694
695                 err = os.WriteFile("/lib/systemd/system/arvados.service", arvadosServiceFile, 0777)
696                 if err != nil {
697                         return 1
698                 }
699                 if prod {
700                         // (fpm will do this for us in the pkg case)
701                         // This is equivalent to "systemd enable", but
702                         // does not depend on the systemctl program
703                         // being available:
704                         symlink := "/etc/systemd/system/multi-user.target.wants/arvados.service"
705                         err = os.Remove(symlink)
706                         if err != nil && !errors.Is(err, os.ErrNotExist) {
707                                 return 1
708                         }
709                         err = os.Symlink("/lib/systemd/system/arvados.service", symlink)
710                         if err != nil {
711                                 return 1
712                         }
713                 }
714
715                 // Add symlinks in /usr/bin for user-facing programs
716                 for _, srcdst := range [][]string{
717                         // go
718                         {"bin/arvados-client"},
719                         {"bin/arvados-client", "arv"},
720                         {"bin/arvados-server"},
721                         // sdk/cli
722                         {"bin/arv", "arv-ruby"},
723                         {"bin/arv-tag"},
724                         // sdk/python
725                         {"lib/python/bin/arv-copy"},
726                         {"lib/python/bin/arv-federation-migrate"},
727                         {"lib/python/bin/arv-get"},
728                         {"lib/python/bin/arv-keepdocker"},
729                         {"lib/python/bin/arv-ls"},
730                         {"lib/python/bin/arv-migrate-docker19"},
731                         {"lib/python/bin/arv-normalize"},
732                         {"lib/python/bin/arv-put"},
733                         {"lib/python/bin/arv-ws"},
734                         // services/fuse
735                         {"lib/python/bin/arv-mount"},
736                 } {
737                         src := "/var/lib/arvados/" + srcdst[0]
738                         if _, err = os.Stat(src); err != nil {
739                                 return 1
740                         }
741                         dst := srcdst[len(srcdst)-1]
742                         _, dst = filepath.Split(dst)
743                         dst = "/usr/bin/" + dst
744                         err = os.Remove(dst)
745                         if err != nil && !errors.Is(err, os.ErrNotExist) {
746                                 return 1
747                         }
748                         err = os.Symlink(src, dst)
749                         if err != nil {
750                                 return 1
751                         }
752                 }
753         }
754
755         return 0
756 }
757
758 type osversion struct {
759         Debian bool
760         Ubuntu bool
761         Centos bool
762         Major  int
763 }
764
765 func identifyOS() (osversion, error) {
766         var osv osversion
767         f, err := os.Open("/etc/os-release")
768         if err != nil {
769                 return osv, err
770         }
771         defer f.Close()
772
773         kv := map[string]string{}
774         scanner := bufio.NewScanner(f)
775         for scanner.Scan() {
776                 line := strings.TrimSpace(scanner.Text())
777                 if strings.HasPrefix(line, "#") {
778                         continue
779                 }
780                 toks := strings.SplitN(line, "=", 2)
781                 if len(toks) != 2 {
782                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
783                 }
784                 k := toks[0]
785                 v := strings.Trim(toks[1], `"`)
786                 if v == toks[1] {
787                         v = strings.Trim(v, `'`)
788                 }
789                 kv[k] = v
790         }
791         if err = scanner.Err(); err != nil {
792                 return osv, err
793         }
794         switch kv["ID"] {
795         case "ubuntu":
796                 osv.Ubuntu = true
797         case "debian":
798                 osv.Debian = true
799         case "centos":
800                 osv.Centos = true
801         default:
802                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
803         }
804         vstr := kv["VERSION_ID"]
805         if i := strings.Index(vstr, "."); i > 0 {
806                 vstr = vstr[:i]
807         }
808         osv.Major, err = strconv.Atoi(vstr)
809         if err != nil {
810                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
811         }
812         return osv, nil
813 }
814
815 func waitPostgreSQLReady() error {
816         for deadline := time.Now().Add(10 * time.Second); ; {
817                 output, err := exec.Command("pg_isready").CombinedOutput()
818                 if err == nil {
819                         return nil
820                 } else if time.Now().After(deadline) {
821                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
822                 } else {
823                         time.Sleep(time.Second)
824                 }
825         }
826 }
827
828 func (inst *installCommand) runBash(script string, stdout, stderr io.Writer) error {
829         cmd := exec.Command("bash", "-")
830         if inst.EatMyData {
831                 cmd = exec.Command("eatmydata", "bash", "-")
832         }
833         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
834         cmd.Stdout = stdout
835         cmd.Stderr = stderr
836         return cmd.Run()
837 }
838
839 func prodpkgs(osv osversion) []string {
840         pkgs := []string{
841                 "ca-certificates",
842                 "curl",
843                 "fuse",
844                 "git",
845                 "gitolite3",
846                 "graphviz",
847                 "haveged",
848                 "libcurl3-gnutls",
849                 "libxslt1.1",
850                 "nginx",
851                 "python3",
852                 "sudo",
853         }
854         if osv.Debian || osv.Ubuntu {
855                 if osv.Debian && osv.Major == 8 {
856                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
857                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
858                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
859                 }
860                 return append(pkgs,
861                         "mime-support", // keep-web
862                 )
863         } else if osv.Centos {
864                 return append(pkgs,
865                         "fuse-libs", // services/fuse
866                         "mailcap",   // keep-web
867                 )
868         } else {
869                 panic("os version not supported")
870         }
871 }
872
873 func ProductionDependencies() ([]string, error) {
874         osv, err := identifyOS()
875         if err != nil {
876                 return nil, err
877         }
878         return prodpkgs(osv), nil
879 }