Merge branch '13645-fix-arvados-api-host-insecure'
[arvados.git] / sdk / cwl / arvados_cwl / arvjob.py
1 # Copyright (C) The Arvados Authors. All rights reserved.
2 #
3 # SPDX-License-Identifier: Apache-2.0
4
5 import logging
6 import re
7 import copy
8 import json
9 import time
10
11 from cwltool.process import shortname, UnsupportedRequirement
12 from cwltool.errors import WorkflowException
13 from cwltool.command_line_tool import revmap_file, CommandLineTool
14 from cwltool.load_tool import fetch_document
15 from cwltool.builder import Builder
16 from cwltool.pathmapper import adjustFileObjs, adjustDirObjs, visit_class
17 from cwltool.job import JobBase
18
19 from schema_salad.sourceline import SourceLine
20
21 from arvados_cwl.util import get_current_container, get_intermediate_collection_info
22 import ruamel.yaml as yaml
23
24 import arvados.collection
25 from arvados.errors import ApiError
26
27 from .arvdocker import arv_docker_get_image
28 from .runner import Runner, arvados_jobs_image, packed_workflow, upload_workflow_collection, trim_anonymous_location, remove_redundant_fields
29 from .pathmapper import VwdPathMapper, trim_listing
30 from .perf import Perf
31 from . import done
32 from ._version import __version__
33
34 logger = logging.getLogger('arvados.cwl-runner')
35 metrics = logging.getLogger('arvados.cwl-runner.metrics')
36
37 crunchrunner_re = re.compile(r"^.*crunchrunner: \$\(task\.(tmpdir|outdir|keep)\)=(.*)$")
38
39 crunchrunner_git_commit = 'a3f2cb186e437bfce0031b024b2157b73ed2717d'
40
41 class ArvadosJob(JobBase):
42     """Submit and manage a Crunch job for executing a CWL CommandLineTool."""
43
44     def __init__(self, runner,
45                  builder,   # type: Builder
46                  joborder,  # type: Dict[Text, Union[Dict[Text, Any], List, Text]]
47                  make_path_mapper,  # type: Callable[..., PathMapper]
48                  requirements,      # type: List[Dict[Text, Text]]
49                  hints,     # type: List[Dict[Text, Text]]
50                  name       # type: Text
51     ):
52         super(ArvadosJob, self).__init__(builder, joborder, make_path_mapper, requirements, hints, name)
53         self.arvrunner = runner
54         self.running = False
55         self.uuid = None
56
57     def run(self, runtimeContext):
58         script_parameters = {
59             "command": self.command_line
60         }
61         runtime_constraints = {}
62
63         with Perf(metrics, "generatefiles %s" % self.name):
64             if self.generatefiles["listing"]:
65                 vwd = arvados.collection.Collection(api_client=self.arvrunner.api,
66                                                     keep_client=self.arvrunner.keep_client,
67                                                     num_retries=self.arvrunner.num_retries)
68                 script_parameters["task.vwd"] = {}
69                 generatemapper = VwdPathMapper([self.generatefiles], "", "",
70                                                separateDirs=False)
71
72                 with Perf(metrics, "createfiles %s" % self.name):
73                     for f, p in generatemapper.items():
74                         if p.type == "CreateFile":
75                             with vwd.open(p.target, "w") as n:
76                                 n.write(p.resolved.encode("utf-8"))
77
78                 if vwd:
79                     with Perf(metrics, "generatefiles.save_new %s" % self.name):
80                         if not runtimeContext.current_container:
81                             runtimeContext.current_container = get_current_container(self.arvrunner.api, self.arvrunner.num_retries, logger)
82                         info = get_intermediate_collection_info(self.name, runtimeContext.current_container, runtimeContext.intermediate_output_ttl)
83                         vwd.save_new(name=info["name"],
84                                      owner_uuid=self.arvrunner.project_uuid,
85                                      ensure_unique_name=True,
86                                      trash_at=info["trash_at"],
87                                      properties=info["properties"])
88
89                 for f, p in generatemapper.items():
90                     if p.type == "File":
91                         script_parameters["task.vwd"][p.target] = p.resolved
92                     if p.type == "CreateFile":
93                         script_parameters["task.vwd"][p.target] = "$(task.keep)/%s/%s" % (vwd.portable_data_hash(), p.target)
94
95         script_parameters["task.env"] = {"TMPDIR": self.tmpdir, "HOME": self.outdir}
96         if self.environment:
97             script_parameters["task.env"].update(self.environment)
98
99         if self.stdin:
100             script_parameters["task.stdin"] = self.stdin
101
102         if self.stdout:
103             script_parameters["task.stdout"] = self.stdout
104
105         if self.stderr:
106             script_parameters["task.stderr"] = self.stderr
107
108         if self.successCodes:
109             script_parameters["task.successCodes"] = self.successCodes
110         if self.temporaryFailCodes:
111             script_parameters["task.temporaryFailCodes"] = self.temporaryFailCodes
112         if self.permanentFailCodes:
113             script_parameters["task.permanentFailCodes"] = self.permanentFailCodes
114
115         with Perf(metrics, "arv_docker_get_image %s" % self.name):
116             (docker_req, docker_is_req) = self.get_requirement("DockerRequirement")
117             if docker_req and runtimeContext.use_container is not False:
118                 if docker_req.get("dockerOutputDirectory"):
119                     raise SourceLine(docker_req, "dockerOutputDirectory", UnsupportedRequirement).makeError(
120                         "Option 'dockerOutputDirectory' of DockerRequirement not supported.")
121                 runtime_constraints["docker_image"] = arv_docker_get_image(self.arvrunner.api,
122                                                                            docker_req,
123                                                                            runtimeContext.pull_image,
124                                                                            self.arvrunner.project_uuid)
125             else:
126                 runtime_constraints["docker_image"] = "arvados/jobs"
127
128         resources = self.builder.resources
129         if resources is not None:
130             runtime_constraints["min_cores_per_node"] = resources.get("cores", 1)
131             runtime_constraints["min_ram_mb_per_node"] = resources.get("ram")
132             runtime_constraints["min_scratch_mb_per_node"] = resources.get("tmpdirSize", 0) + resources.get("outdirSize", 0)
133
134         runtime_req, _ = self.get_requirement("http://arvados.org/cwl#RuntimeConstraints")
135         if runtime_req:
136             if "keep_cache" in runtime_req:
137                 runtime_constraints["keep_cache_mb_per_task"] = runtime_req["keep_cache"]
138                 runtime_constraints["min_ram_mb_per_node"] += runtime_req["keep_cache"]
139             if "outputDirType" in runtime_req:
140                 if runtime_req["outputDirType"] == "local_output_dir":
141                     script_parameters["task.keepTmpOutput"] = False
142                 elif runtime_req["outputDirType"] == "keep_output_dir":
143                     script_parameters["task.keepTmpOutput"] = True
144
145         filters = [["repository", "=", "arvados"],
146                    ["script", "=", "crunchrunner"],
147                    ["script_version", "in git", crunchrunner_git_commit]]
148         if not self.arvrunner.ignore_docker_for_reuse:
149             filters.append(["docker_image_locator", "in docker", runtime_constraints["docker_image"]])
150
151         enable_reuse = runtimeContext.enable_reuse
152         if enable_reuse:
153             reuse_req, _ = self.get_requirement("http://arvados.org/cwl#ReuseRequirement")
154             if reuse_req:
155                 enable_reuse = reuse_req["enableReuse"]
156
157         self.output_callback = self.arvrunner.get_wrapped_callback(self.output_callback)
158
159         try:
160             with Perf(metrics, "create %s" % self.name):
161                 response = self.arvrunner.api.jobs().create(
162                     body={
163                         "owner_uuid": self.arvrunner.project_uuid,
164                         "script": "crunchrunner",
165                         "repository": "arvados",
166                         "script_version": "master",
167                         "minimum_script_version": crunchrunner_git_commit,
168                         "script_parameters": {"tasks": [script_parameters]},
169                         "runtime_constraints": runtime_constraints
170                     },
171                     filters=filters,
172                     find_or_create=enable_reuse
173                 ).execute(num_retries=self.arvrunner.num_retries)
174
175             self.uuid = response["uuid"]
176             self.arvrunner.process_submitted(self)
177
178             self.update_pipeline_component(response)
179
180             if response["state"] == "Complete":
181                 logger.info("%s reused job %s", self.arvrunner.label(self), response["uuid"])
182                 # Give read permission to the desired project on reused jobs
183                 if response["owner_uuid"] != self.arvrunner.project_uuid:
184                     try:
185                         self.arvrunner.api.links().create(body={
186                             'link_class': 'permission',
187                             'name': 'can_read',
188                             'tail_uuid': self.arvrunner.project_uuid,
189                             'head_uuid': response["uuid"],
190                             }).execute(num_retries=self.arvrunner.num_retries)
191                     except ApiError as e:
192                         # The user might not have "manage" access on the job: log
193                         # a message and continue.
194                         logger.info("Creating read permission on job %s: %s",
195                                     response["uuid"],
196                                     e)
197             else:
198                 logger.info("%s %s is %s", self.arvrunner.label(self), response["uuid"], response["state"])
199         except Exception as e:
200             logger.exception("%s error" % (self.arvrunner.label(self)))
201             self.output_callback({}, "permanentFail")
202
203     def update_pipeline_component(self, record):
204         with self.arvrunner.workflow_eval_lock:
205             if self.arvrunner.pipeline:
206                 self.arvrunner.pipeline["components"][self.name] = {"job": record}
207                 with Perf(metrics, "update_pipeline_component %s" % self.name):
208                     self.arvrunner.pipeline = self.arvrunner.api.pipeline_instances().update(
209                         uuid=self.arvrunner.pipeline["uuid"],
210                         body={
211                             "components": self.arvrunner.pipeline["components"]
212                         }).execute(num_retries=self.arvrunner.num_retries)
213             if self.arvrunner.uuid:
214                 try:
215                     job = self.arvrunner.api.jobs().get(uuid=self.arvrunner.uuid).execute()
216                     if job:
217                         components = job["components"]
218                         components[self.name] = record["uuid"]
219                         self.arvrunner.api.jobs().update(
220                             uuid=self.arvrunner.uuid,
221                             body={
222                                 "components": components
223                             }).execute(num_retries=self.arvrunner.num_retries)
224                 except Exception as e:
225                     logger.info("Error adding to components: %s", e)
226
227     def done(self, record):
228         try:
229             self.update_pipeline_component(record)
230         except:
231             pass
232
233         try:
234             if record["state"] == "Complete":
235                 processStatus = "success"
236             else:
237                 processStatus = "permanentFail"
238
239             outputs = {}
240             try:
241                 if record["output"]:
242                     with Perf(metrics, "inspect log %s" % self.name):
243                         logc = arvados.collection.CollectionReader(record["log"],
244                                                                    api_client=self.arvrunner.api,
245                                                                    keep_client=self.arvrunner.keep_client,
246                                                                    num_retries=self.arvrunner.num_retries)
247                         log = logc.open(logc.keys()[0])
248                         dirs = {
249                             "tmpdir": "/tmpdir",
250                             "outdir": "/outdir",
251                             "keep": "/keep"
252                         }
253                         for l in log:
254                             # Determine the tmpdir, outdir and keep paths from
255                             # the job run.  Unfortunately, we can't take the first
256                             # values we find (which are expected to be near the
257                             # top) and stop scanning because if the node fails and
258                             # the job restarts on a different node these values
259                             # will different runs, and we need to know about the
260                             # final run that actually produced output.
261                             g = crunchrunner_re.match(l)
262                             if g:
263                                 dirs[g.group(1)] = g.group(2)
264
265                     if processStatus == "permanentFail":
266                         done.logtail(logc, logger.error, "%s (%s) error log:" % (self.arvrunner.label(self), record["uuid"]), maxlen=40)
267
268                     with Perf(metrics, "output collection %s" % self.name):
269                         outputs = done.done(self, record, dirs["tmpdir"],
270                                             dirs["outdir"], dirs["keep"])
271             except WorkflowException as e:
272                 logger.error("%s unable to collect output from %s:\n%s",
273                              self.arvrunner.label(self), record["output"], e, exc_info=(e if self.arvrunner.debug else False))
274                 processStatus = "permanentFail"
275             except Exception as e:
276                 logger.exception("Got unknown exception while collecting output for job %s:", self.name)
277                 processStatus = "permanentFail"
278
279             # Note: Currently, on error output_callback is expecting an empty dict,
280             # anything else will fail.
281             if not isinstance(outputs, dict):
282                 logger.error("Unexpected output type %s '%s'", type(outputs), outputs)
283                 outputs = {}
284                 processStatus = "permanentFail"
285         finally:
286             self.output_callback(outputs, processStatus)
287
288
289 class RunnerJob(Runner):
290     """Submit and manage a Crunch job that runs crunch_scripts/cwl-runner."""
291
292     def arvados_job_spec(self, debug=False):
293         """Create an Arvados job specification for this workflow.
294
295         The returned dict can be used to create a job (i.e., passed as
296         the +body+ argument to jobs().create()), or as a component in
297         a pipeline template or pipeline instance.
298         """
299
300         if self.tool.tool["id"].startswith("keep:"):
301             self.job_order["cwl:tool"] = self.tool.tool["id"][5:]
302         else:
303             packed = packed_workflow(self.arvrunner, self.tool, self.merged_map)
304             wf_pdh = upload_workflow_collection(self.arvrunner, self.name, packed)
305             self.job_order["cwl:tool"] = "%s/workflow.cwl#main" % wf_pdh
306
307         adjustDirObjs(self.job_order, trim_listing)
308         visit_class(self.job_order, ("File", "Directory"), trim_anonymous_location)
309         visit_class(self.job_order, ("File", "Directory"), remove_redundant_fields)
310
311         if self.output_name:
312             self.job_order["arv:output_name"] = self.output_name
313
314         if self.output_tags:
315             self.job_order["arv:output_tags"] = self.output_tags
316
317         self.job_order["arv:enable_reuse"] = self.enable_reuse
318
319         if self.on_error:
320             self.job_order["arv:on_error"] = self.on_error
321
322         if debug:
323             self.job_order["arv:debug"] = True
324
325         return {
326             "script": "cwl-runner",
327             "script_version": "master",
328             "minimum_script_version": "570509ab4d2ef93d870fd2b1f2eab178afb1bad9",
329             "repository": "arvados",
330             "script_parameters": self.job_order,
331             "runtime_constraints": {
332                 "docker_image": arvados_jobs_image(self.arvrunner, self.jobs_image),
333                 "min_ram_mb_per_node": self.submit_runner_ram
334             }
335         }
336
337     def run(self, runtimeContext):
338         job_spec = self.arvados_job_spec(runtimeContext.debug)
339
340         job_spec.setdefault("owner_uuid", self.arvrunner.project_uuid)
341
342         job = self.arvrunner.api.jobs().create(
343             body=job_spec,
344             find_or_create=self.enable_reuse
345         ).execute(num_retries=self.arvrunner.num_retries)
346
347         for k,v in job_spec["script_parameters"].items():
348             if v is False or v is None or isinstance(v, dict):
349                 job_spec["script_parameters"][k] = {"value": v}
350
351         del job_spec["owner_uuid"]
352         job_spec["job"] = job
353
354         instance_spec = {
355             "owner_uuid": self.arvrunner.project_uuid,
356             "name": self.name,
357             "components": {
358                 "cwl-runner": job_spec,
359             },
360             "state": "RunningOnServer",
361         }
362         if not self.enable_reuse:
363             instance_spec["properties"] = {"run_options": {"enable_job_reuse": False}}
364
365         self.arvrunner.pipeline = self.arvrunner.api.pipeline_instances().create(
366             body=instance_spec).execute(num_retries=self.arvrunner.num_retries)
367         logger.info("Created pipeline %s", self.arvrunner.pipeline["uuid"])
368
369         if runtimeContext.wait is False:
370             self.uuid = self.arvrunner.pipeline["uuid"]
371             return
372
373         self.uuid = job["uuid"]
374         self.arvrunner.process_submitted(self)
375
376
377 class RunnerTemplate(object):
378     """An Arvados pipeline template that invokes a CWL workflow."""
379
380     type_to_dataclass = {
381         'boolean': 'boolean',
382         'File': 'File',
383         'Directory': 'Collection',
384         'float': 'number',
385         'int': 'number',
386         'string': 'text',
387     }
388
389     def __init__(self, runner, tool, job_order, enable_reuse, uuid,
390                  submit_runner_ram=0, name=None, merged_map=None):
391         self.runner = runner
392         self.tool = tool
393         self.job = RunnerJob(
394             runner=runner,
395             tool=tool,
396             job_order=job_order,
397             enable_reuse=enable_reuse,
398             output_name=None,
399             output_tags=None,
400             submit_runner_ram=submit_runner_ram,
401             name=name,
402             merged_map=merged_map)
403         self.uuid = uuid
404
405     def pipeline_component_spec(self):
406         """Return a component that Workbench and a-r-p-i will understand.
407
408         Specifically, translate CWL input specs to Arvados pipeline
409         format, like {"dataclass":"File","value":"xyz"}.
410         """
411
412         spec = self.job.arvados_job_spec()
413
414         # Most of the component spec is exactly the same as the job
415         # spec (script, script_version, etc.).
416         # spec['script_parameters'] isn't right, though. A component
417         # spec's script_parameters hash is a translation of
418         # self.tool.tool['inputs'] with defaults/overrides taken from
419         # the job order. So we move the job parameters out of the way
420         # and build a new spec['script_parameters'].
421         job_params = spec['script_parameters']
422         spec['script_parameters'] = {}
423
424         for param in self.tool.tool['inputs']:
425             param = copy.deepcopy(param)
426
427             # Data type and "required" flag...
428             types = param['type']
429             if not isinstance(types, list):
430                 types = [types]
431             param['required'] = 'null' not in types
432             non_null_types = [t for t in types if t != "null"]
433             if len(non_null_types) == 1:
434                 the_type = [c for c in non_null_types][0]
435                 dataclass = None
436                 if isinstance(the_type, basestring):
437                     dataclass = self.type_to_dataclass.get(the_type)
438                 if dataclass:
439                     param['dataclass'] = dataclass
440             # Note: If we didn't figure out a single appropriate
441             # dataclass, we just left that attribute out.  We leave
442             # the "type" attribute there in any case, which might help
443             # downstream.
444
445             # Title and description...
446             title = param.pop('label', '')
447             descr = param.pop('doc', '').rstrip('\n')
448             if title:
449                 param['title'] = title
450             if descr:
451                 param['description'] = descr
452
453             # Fill in the value from the current job order, if any.
454             param_id = shortname(param.pop('id'))
455             value = job_params.get(param_id)
456             if value is None:
457                 pass
458             elif not isinstance(value, dict):
459                 param['value'] = value
460             elif param.get('dataclass') in ('File', 'Collection') and value.get('location'):
461                 param['value'] = value['location'][5:]
462
463             spec['script_parameters'][param_id] = param
464         spec['script_parameters']['cwl:tool'] = job_params['cwl:tool']
465         return spec
466
467     def save(self):
468         body = {
469             "components": {
470                 self.job.name: self.pipeline_component_spec(),
471             },
472             "name": self.job.name,
473         }
474         if self.runner.project_uuid:
475             body["owner_uuid"] = self.runner.project_uuid
476         if self.uuid:
477             self.runner.api.pipeline_templates().update(
478                 uuid=self.uuid, body=body).execute(
479                     num_retries=self.runner.num_retries)
480             logger.info("Updated template %s", self.uuid)
481         else:
482             self.uuid = self.runner.api.pipeline_templates().create(
483                 body=body, ensure_unique_name=True).execute(
484                     num_retries=self.runner.num_retries)['uuid']
485             logger.info("Created template %s", self.uuid)