18874: Embed real git commit in wb2 build.
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         _ "embed"
12         "errors"
13         "flag"
14         "fmt"
15         "io"
16         "os"
17         "os/exec"
18         "os/user"
19         "path/filepath"
20         "runtime"
21         "strconv"
22         "strings"
23         "syscall"
24         "time"
25
26         "git.arvados.org/arvados.git/lib/cmd"
27         "git.arvados.org/arvados.git/sdk/go/ctxlog"
28         "github.com/lib/pq"
29 )
30
31 var Command cmd.Handler = &installCommand{}
32
33 const goversion = "1.20.6"
34
35 const (
36         rubyversion             = "2.7.7"
37         bundlerversion          = "2.2.19"
38         singularityversion      = "3.10.4"
39         pjsversion              = "1.9.8"
40         geckoversion            = "0.24.0"
41         gradleversion           = "5.3.1"
42         nodejsversion           = "v12.22.12"
43         devtestDatabasePassword = "insecure_arvados_test"
44 )
45
46 //go:embed arvados.service
47 var arvadosServiceFile []byte
48
49 type installCommand struct {
50         ClusterType    string
51         SourcePath     string
52         Commit         string
53         PackageVersion string
54         EatMyData      bool
55 }
56
57 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
58         logger := ctxlog.New(stderr, "text", "info")
59         ctx := ctxlog.Context(context.Background(), logger)
60         ctx, cancel := context.WithCancel(ctx)
61         defer cancel()
62
63         var err error
64         defer func() {
65                 if err != nil {
66                         logger.WithError(err).Info("exiting")
67                 }
68         }()
69
70         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
71         flags.SetOutput(stderr)
72         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
73         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
74         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
75         flags.StringVar(&inst.Commit, "commit", "", "source commit `hash` to embed (blank means use 'git log' or all-zero placeholder)")
76         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
77         flags.BoolVar(&inst.EatMyData, "eatmydata", false, "use eatmydata to speed up install")
78
79         if ok, code := cmd.ParseFlags(flags, prog, args, "", stderr); !ok {
80                 return code
81         } else if *versionFlag {
82                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
83         }
84
85         if inst.Commit == "" {
86                 if commit, err := exec.Command("env", "-C", inst.SourcePath, "git", "log", "-n1", "--format=%H").CombinedOutput(); err == nil {
87                         inst.Commit = strings.TrimSpace(string(commit))
88                 } else {
89                         inst.Commit = "0000000000000000000000000000000000000000"
90                 }
91         }
92
93         var dev, test, prod, pkg bool
94         switch inst.ClusterType {
95         case "development":
96                 dev = true
97         case "test":
98                 test = true
99         case "production":
100                 prod = true
101         case "package":
102                 pkg = true
103         default:
104                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
105                 return 2
106         }
107
108         if prod {
109                 err = errors.New("production install is not yet implemented")
110                 return 1
111         }
112
113         osv, err := identifyOS()
114         if err != nil {
115                 return 1
116         }
117
118         listdir, err := os.Open("/var/lib/apt/lists")
119         if err != nil {
120                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
121         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
122                 // Special case for a base docker image where the
123                 // package cache has been deleted and all "apt-get
124                 // install" commands will fail unless we fetch repos.
125                 cmd := exec.CommandContext(ctx, "apt-get", "update")
126                 cmd.Stdout = stdout
127                 cmd.Stderr = stderr
128                 err = cmd.Run()
129                 if err != nil {
130                         return 1
131                 }
132         }
133
134         if inst.EatMyData {
135                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends", "eatmydata")
136                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
137                 cmd.Stdout = stdout
138                 cmd.Stderr = stderr
139                 err = cmd.Run()
140                 if err != nil {
141                         return 1
142                 }
143         }
144
145         pkgs := prodpkgs(osv)
146
147         if pkg {
148                 pkgs = append(pkgs,
149                         "dpkg-dev",
150                         "eatmydata", // install it for later steps, even if we're not using it now
151                 )
152         }
153
154         if dev || test || pkg {
155                 pkgs = append(pkgs,
156                         "automake",
157                         "bison",
158                         "bsdmainutils",
159                         "build-essential",
160                         "cadaver",
161                         "curl",
162                         "cython3",
163                         "default-jdk-headless",
164                         "default-jre-headless",
165                         "gettext",
166                         "libattr1-dev",
167                         "libfuse-dev",
168                         "libgbm1", // cypress / workbench2 tests
169                         "libgnutls28-dev",
170                         "libpam-dev",
171                         "libpcre3-dev",
172                         "libpq-dev",
173                         "libreadline-dev",
174                         "libssl-dev",
175                         "libxml2-dev",
176                         "libxslt1-dev",
177                         "linkchecker",
178                         "lsof",
179                         "make",
180                         "net-tools",
181                         "pandoc",
182                         "pkg-config",
183                         "postgresql",
184                         "postgresql-contrib",
185                         "python3-dev",
186                         "python3-venv",
187                         "python3-virtualenv",
188                         "r-base",
189                         "r-cran-testthat",
190                         "r-cran-devtools",
191                         "r-cran-knitr",
192                         "r-cran-markdown",
193                         "r-cran-roxygen2",
194                         "r-cran-xml",
195                         "rsync",
196                         "sudo",
197                         "uuid-dev",
198                         "wget",
199                         "xvfb",
200                         "zlib1g-dev", // services/api
201                 )
202                 if test {
203                         if osv.Debian && osv.Major <= 10 {
204                                 pkgs = append(pkgs, "iceweasel")
205                         } else if osv.Debian && osv.Major >= 11 {
206                                 pkgs = append(pkgs, "firefox-esr")
207                         } else {
208                                 pkgs = append(pkgs, "firefox")
209                         }
210                 }
211                 if dev || test {
212                         pkgs = append(pkgs,
213                                 "libglib2.0-dev", // singularity (conmon)
214                                 "libseccomp-dev", // singularity (seccomp)
215                                 "squashfs-tools", // singularity
216                                 "gnupg")          // docker install recipe
217                 }
218                 switch {
219                 case osv.Debian && osv.Major >= 11:
220                         pkgs = append(pkgs, "g++", "libcurl4", "libcurl4-openssl-dev")
221                 case osv.Debian && osv.Major >= 10:
222                         pkgs = append(pkgs, "g++", "libcurl4", "libcurl4-openssl-dev")
223                 case osv.Debian || osv.Ubuntu:
224                         pkgs = append(pkgs, "g++", "libcurl3", "libcurl3-openssl-dev")
225                 case osv.Centos:
226                         pkgs = append(pkgs, "gcc", "gcc-c++", "libcurl-devel", "postgresql-devel")
227                 }
228                 cmd := exec.CommandContext(ctx, "apt-get")
229                 if inst.EatMyData {
230                         cmd = exec.CommandContext(ctx, "eatmydata", "apt-get")
231                 }
232                 cmd.Args = append(cmd.Args, "install", "--yes", "--no-install-recommends")
233                 cmd.Args = append(cmd.Args, pkgs...)
234                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
235                 cmd.Stdout = stdout
236                 cmd.Stderr = stderr
237                 err = cmd.Run()
238                 if err != nil {
239                         return 1
240                 }
241         }
242
243         if dev || test {
244                 if havedockerversion, err2 := exec.Command("docker", "--version").CombinedOutput(); err2 == nil {
245                         logger.Printf("%s installed, assuming that version is ok", bytes.TrimSuffix(havedockerversion, []byte("\n")))
246                 } else if osv.Debian {
247                         var codename string
248                         switch osv.Major {
249                         case 10:
250                                 codename = "buster"
251                         case 11:
252                                 codename = "bullseye"
253                         case 12:
254                                 codename = "bookworm"
255                         default:
256                                 err = fmt.Errorf("don't know how to install docker-ce for debian %d", osv.Major)
257                                 return 1
258                         }
259                         err = inst.runBash(`
260 rm -f /usr/share/keyrings/docker-archive-keyring.gpg
261 curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
262 echo 'deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian/ `+codename+` stable' | \
263     tee /etc/apt/sources.list.d/docker.list
264 apt-get update
265 DEBIAN_FRONTEND=noninteractive apt-get --yes --no-install-recommends install docker-ce
266 `, stdout, stderr)
267                         if err != nil {
268                                 return 1
269                         }
270                 } else {
271                         err = fmt.Errorf("don't know how to install docker for osversion %v", osv)
272                         return 1
273                 }
274
275                 err = inst.runBash(`
276 key=fs.inotify.max_user_watches
277 min=524288
278 if [[ "$(sysctl --values "${key}")" -lt "${min}" ]]; then
279     sysctl "${key}=${min}"
280     # writing sysctl worked, so we should make it permanent
281     echo "${key}=${min}" | tee -a /etc/sysctl.conf
282     sysctl -p
283 fi
284 `, stdout, stderr)
285                 if err != nil {
286                         err = fmt.Errorf("couldn't set fs.inotify.max_user_watches value. (Is this a docker container? Fix this on the docker host by adding fs.inotify.max_user_watches=524288 to /etc/sysctl.conf and running `sysctl -p`)")
287                         return 1
288                 }
289         }
290
291         os.Mkdir("/var/lib/arvados", 0755)
292         os.Mkdir("/var/lib/arvados/tmp", 0700)
293         if prod || pkg {
294                 u, er := user.Lookup("www-data")
295                 if er != nil {
296                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
297                         return 1
298                 }
299                 uid, _ := strconv.Atoi(u.Uid)
300                 gid, _ := strconv.Atoi(u.Gid)
301                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
302                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
303                 if err != nil {
304                         return 1
305                 }
306         }
307         rubymajorversion := rubyversion[:strings.LastIndex(rubyversion, ".")]
308         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+rubyversion)) {
309                 logger.Print("ruby " + rubyversion + " already installed")
310         } else {
311                 err = inst.runBash(`
312 tmp="$(mktemp -d)"
313 trap 'rm -r "${tmp}"' ERR EXIT
314 wget --progress=dot:giga -O- https://cache.ruby-lang.org/pub/ruby/`+rubymajorversion+`/ruby-`+rubyversion+`.tar.gz | tar -C "${tmp}" -xzf -
315 cd "${tmp}/ruby-`+rubyversion+`"
316 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
317 make -j8
318 make install
319 /var/lib/arvados/bin/gem install bundler --no-document
320 `, stdout, stderr)
321                 if err != nil {
322                         return 1
323                 }
324         }
325
326         if !prod {
327                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
328                         logger.Print("go " + goversion + " already installed")
329                 } else {
330                         err = inst.runBash(`
331 cd /tmp
332 rm -rf /var/lib/arvados/go/
333 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
334 ln -sfv /var/lib/arvados/go/bin/* /usr/local/bin/
335 `, stdout, stderr)
336                         if err != nil {
337                                 return 1
338                         }
339                 }
340         }
341
342         if !prod && !pkg {
343                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
344                         logger.Print("phantomjs " + pjsversion + " already installed")
345                 } else {
346                         err = inst.runBash(`
347 PJS=phantomjs-`+pjsversion+`-linux-x86_64
348 wget --progress=dot:giga -O- https://cache.arvados.org/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
349 ln -sfv /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
350 `, stdout, stderr)
351                         if err != nil {
352                                 return 1
353                         }
354                 }
355
356                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
357                         logger.Print("geckodriver " + geckoversion + " already installed")
358                 } else {
359                         err = inst.runBash(`
360 GD=v`+geckoversion+`
361 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
362 ln -sfv /var/lib/arvados/bin/geckodriver /usr/local/bin/
363 `, stdout, stderr)
364                         if err != nil {
365                                 return 1
366                         }
367                 }
368
369                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
370                         logger.Print("gradle " + gradleversion + " already installed")
371                 } else {
372                         err = inst.runBash(`
373 G=`+gradleversion+`
374 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
375 trap "rm ${zip}" ERR
376 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
377 unzip -o -d /var/lib/arvados ${zip}
378 ln -sfv /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
379 rm ${zip}
380 `, stdout, stderr)
381                         if err != nil {
382                                 return 1
383                         }
384                 }
385
386                 if havesingularityversion, err := exec.Command("/var/lib/arvados/bin/singularity", "--version").CombinedOutput(); err == nil && strings.Contains(string(havesingularityversion), singularityversion) {
387                         logger.Print("singularity " + singularityversion + " already installed")
388                 } else if dev || test {
389                         err = inst.runBash(`
390 S=`+singularityversion+`
391 tmp=/var/lib/arvados/tmp/singularity
392 trap "rm -r ${tmp}" ERR EXIT
393 cd /var/lib/arvados/tmp
394 git clone --recurse-submodules https://github.com/sylabs/singularity
395 cd singularity
396 git checkout v${S}
397 ./mconfig --prefix=/var/lib/arvados
398 make -C ./builddir
399 make -C ./builddir install
400 `, stdout, stderr)
401                         if err != nil {
402                                 return 1
403                         }
404                 }
405
406                 err = inst.runBash(`
407 install /usr/bin/nsenter /var/lib/arvados/bin/nsenter
408 setcap "cap_sys_admin+pei cap_sys_chroot+pei" /var/lib/arvados/bin/nsenter
409 `, stdout, stderr)
410                 if err != nil {
411                         return 1
412                 }
413
414                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
415                 // it's installed, locale -a reports it as
416                 // "en_US.utf8".
417                 wantlocale := "en_US.UTF-8"
418                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
419                         logger.Print("locale " + wantlocale + " already installed")
420                 } else {
421                         err = inst.runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
422                         if err != nil {
423                                 return 1
424                         }
425                 }
426
427                 var pgc struct {
428                         Version       string
429                         Cluster       string
430                         Port          int
431                         Status        string
432                         Owner         string
433                         DataDirectory string
434                         LogFile       string
435                 }
436                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
437                         err = fmt.Errorf("pg_lsclusters: %s", err2)
438                         return 1
439                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
440                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
441                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
442                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
443                         return 1
444                 } else if pgc.Status == "online" {
445                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
446                 } else {
447                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
448                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
449                         cmd.Stdout = stdout
450                         cmd.Stderr = stderr
451                         err = cmd.Start()
452                         if err != nil {
453                                 return 1
454                         }
455                         defer func() {
456                                 cmd.Process.Signal(syscall.SIGTERM)
457                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
458                                 cmd.Wait()
459                         }()
460                         err = waitPostgreSQLReady()
461                         if err != nil {
462                                 return 1
463                         }
464                 }
465
466                 if os.Getpid() == 1 {
467                         // We are the init process (presumably in a
468                         // docker container) so although postgresql is
469                         // installed, it's not running, and initdb
470                         // might never have been run.
471                 }
472
473                 var needcoll []string
474                 // If the en_US.UTF-8 locale wasn't installed when
475                 // postgresql initdb ran, it needs to be added
476                 // explicitly before we can use it in our test suite.
477                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
478                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
479                         cmd.Dir = "/"
480                         out, err2 := cmd.CombinedOutput()
481                         if err != nil {
482                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
483                                 return 1
484                         }
485                         if strings.Contains(string(out), "1") {
486                                 logger.Infof("postgresql supports collation %s", collname)
487                         } else {
488                                 needcoll = append(needcoll, collname)
489                         }
490                 }
491                 if len(needcoll) > 0 && os.Getpid() != 1 {
492                         // In order for the CREATE COLLATION statement
493                         // below to work, the locale must have existed
494                         // when PostgreSQL started up. If we're
495                         // running as init, we must have started
496                         // PostgreSQL ourselves after installing the
497                         // locales. Otherwise, it might need a
498                         // restart, so we attempt to restart it with
499                         // systemd.
500                         if err = inst.runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
501                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
502                         } else if err = waitPostgreSQLReady(); err != nil {
503                                 return 1
504                         }
505                 }
506                 for _, collname := range needcoll {
507                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
508                         cmd.Stdout = stdout
509                         cmd.Stderr = stderr
510                         cmd.Dir = "/"
511                         err = cmd.Run()
512                         if err != nil {
513                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
514                                 return 1
515                         }
516                 }
517
518                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
519                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
520                 cmd.Dir = "/"
521                 if err := cmd.Run(); err == nil {
522                         logger.Print("arvados role exists; superuser privileges added, password updated")
523                 } else {
524                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
525                         cmd.Dir = "/"
526                         cmd.Stdout = stdout
527                         cmd.Stderr = stderr
528                         err = cmd.Run()
529                         if err != nil {
530                                 return 1
531                         }
532                 }
533         }
534
535         if !prod {
536                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == nodejsversion+"\n" {
537                         logger.Print("nodejs " + nodejsversion + " already installed")
538                 } else {
539                         err = inst.runBash(`
540 NJS=`+nodejsversion+`
541 rm -rf /var/lib/arvados/node-*-linux-x64
542 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
543 ln -sfv /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
544 `, stdout, stderr)
545                         if err != nil {
546                                 return 1
547                         }
548                 }
549
550                 if haveyarnversion, err := exec.Command("/usr/local/bin/yarn", "--version").CombinedOutput(); err == nil && len(haveyarnversion) > 0 {
551                         logger.Print("yarn " + strings.TrimSpace(string(haveyarnversion)) + " already installed")
552                 } else {
553                         err = inst.runBash(`
554 npm install -g yarn
555 ln -sfv /var/lib/arvados/node-`+nodejsversion+`-linux-x64/bin/{yarn,yarnpkg} /usr/local/bin/
556 `, stdout, stderr)
557                         if err != nil {
558                                 return 1
559                         }
560                 }
561         }
562
563         if prod || pkg {
564                 // Install Go programs to /var/lib/arvados/bin/
565                 for _, srcdir := range []string{
566                         "cmd/arvados-client",
567                         "cmd/arvados-server",
568                 } {
569                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
570                         // -buildvcs=false here avoids a fatal "error
571                         // obtaining VCS status" when git refuses to
572                         // run (for example) as root in a docker
573                         // container using a non-root-owned git tree
574                         // mounted from the host -- as in
575                         // "arvados-package build".
576                         cmd := exec.Command("go", "install", "-buildvcs=false",
577                                 "-ldflags", "-s -w"+
578                                         " -X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+
579                                         " -X git.arvados.org/arvados.git/lib/cmd.commit="+inst.Commit)
580                         cmd.Env = append(cmd.Env, os.Environ()...)
581                         cmd.Env = append(cmd.Env, "GOBIN=/var/lib/arvados/bin")
582                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
583                         cmd.Stdout = stdout
584                         cmd.Stderr = stderr
585                         err = cmd.Run()
586                         if err != nil {
587                                 return 1
588                         }
589                 }
590
591                 // Copy assets from source tree to /var/lib/arvados/share
592                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
593                 cmd.Stdout = stdout
594                 cmd.Stderr = stderr
595                 err = cmd.Run()
596                 if err != nil {
597                         return 1
598                 }
599
600                 // Install python SDK and arv-mount in
601                 // /var/lib/arvados/lib/python.
602                 //
603                 // setup.py writes a file in the source directory in
604                 // order to include the version number in the package
605                 // itself.  We don't want to write to the source tree
606                 // (in "arvados-package" context it's mounted
607                 // readonly) so we run setup.py in a temporary copy of
608                 // the source dir.
609                 if err = inst.runBash(`
610 v=/var/lib/arvados/lib/python
611 tmp=/var/lib/arvados/tmp/python
612 python3 -m venv "$v"
613 . "$v/bin/activate"
614 pip3 install --no-cache-dir 'setuptools>=68' 'pip>=20'
615 export ARVADOS_BUILDING_VERSION="`+inst.PackageVersion+`"
616 for src in "`+inst.SourcePath+`/sdk/python" "`+inst.SourcePath+`/services/fuse"; do
617   rsync -a --delete-after "$src/" "$tmp/"
618   cd "$tmp"
619   python3 setup.py install
620   cd ..
621   rm -rf "$tmp"
622 done
623 `, stdout, stderr); err != nil {
624                         return 1
625                 }
626
627                 // Install Rails apps to /var/lib/arvados/{railsapi,workbench1}/
628                 for dstdir, srcdir := range map[string]string{
629                         "railsapi":   "services/api",
630                         "workbench1": "apps/workbench",
631                 } {
632                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
633                         cmd := exec.Command("rsync",
634                                 "-a", "--no-owner", "--no-group", "--delete-after", "--delete-excluded",
635                                 "--exclude", "/coverage",
636                                 "--exclude", "/log",
637                                 "--exclude", "/node_modules",
638                                 "--exclude", "/tmp",
639                                 "--exclude", "/public/assets",
640                                 "--exclude", "/vendor",
641                                 "--exclude", "/config/environments",
642                                 "./", "/var/lib/arvados/"+dstdir+"/")
643                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
644                         cmd.Stdout = stdout
645                         cmd.Stderr = stderr
646                         err = cmd.Run()
647                         if err != nil {
648                                 return 1
649                         }
650                         for _, cmdline := range [][]string{
651                                 {"mkdir", "-p", "log", "public/assets", "tmp", "vendor", ".bundle", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger"},
652                                 {"touch", "log/production.log"},
653                                 {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger", "log", "tmp", "vendor", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
654                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:" + bundlerversion},
655                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "deployment", "true"},
656                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "path", "/var/www/.gem"},
657                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "without", "development test diagnostics performance"},
658                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--jobs", fmt.Sprintf("%d", runtime.NumCPU())},
659
660                                 {"chown", "www-data:www-data", ".", "public/assets"},
661                                 // {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "system", "true"},
662                                 {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "npm:install"},
663                                 {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "assets:precompile"},
664                                 {"chown", "root:root", "."},
665                                 {"chown", "-R", "root:root", "public/assets", "vendor"},
666
667                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
668                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
669                         } {
670                                 if cmdline[len(cmdline)-2] == "rake" && dstdir != "workbench1" {
671                                         continue
672                                 }
673                                 cmd = exec.Command(cmdline[0], cmdline[1:]...)
674                                 cmd.Dir = "/var/lib/arvados/" + dstdir
675                                 cmd.Stdout = stdout
676                                 cmd.Stderr = stderr
677                                 fmt.Fprintf(stderr, "... %s\n", cmd.Args)
678                                 err = cmd.Run()
679                                 if err != nil {
680                                         return 1
681                                 }
682                         }
683                         cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
684                         cmd.Dir = "/var/lib/arvados/" + dstdir
685                         cmd.Stdout = stdout
686                         cmd.Stderr = stderr
687                         err = cmd.Run()
688                         if err != nil && !strings.Contains(err.Error(), "exit status 2") {
689                                 // Exit code 2 indicates there were warnings (like
690                                 // "other passenger installations have been detected",
691                                 // which we can't expect to avoid) but no errors.
692                                 // Other non-zero exit codes (1, 9) indicate errors.
693                                 return 1
694                         }
695                 }
696
697                 // Install workbench2 app to /var/lib/arvados/workbench2/
698                 if err = inst.runBash(`
699 cd "`+inst.SourcePath+`/services/workbench2"
700 VERSION="`+inst.PackageVersion+`" BUILD_NUMBER=1 GIT_COMMIT="`+inst.Commit[:9]+`" yarn build
701 rsync -a --delete-after build/ /var/lib/arvados/workbench2/
702 `, stdout, stderr); err != nil {
703                         return 1
704                 }
705
706                 // Install arvados-cli gem (binaries go in
707                 // /var/lib/arvados/bin)
708                 if err = inst.runBash(`
709 /var/lib/arvados/bin/gem install --conservative --no-document arvados-cli
710 `, stdout, stderr); err != nil {
711                         return 1
712                 }
713
714                 err = os.WriteFile("/lib/systemd/system/arvados.service", arvadosServiceFile, 0777)
715                 if err != nil {
716                         return 1
717                 }
718                 if prod {
719                         // (fpm will do this for us in the pkg case)
720                         // This is equivalent to "systemd enable", but
721                         // does not depend on the systemctl program
722                         // being available:
723                         symlink := "/etc/systemd/system/multi-user.target.wants/arvados.service"
724                         err = os.Remove(symlink)
725                         if err != nil && !errors.Is(err, os.ErrNotExist) {
726                                 return 1
727                         }
728                         err = os.Symlink("/lib/systemd/system/arvados.service", symlink)
729                         if err != nil {
730                                 return 1
731                         }
732                 }
733
734                 // Add symlinks in /usr/bin for user-facing programs
735                 for _, srcdst := range [][]string{
736                         // go
737                         {"bin/arvados-client"},
738                         {"bin/arvados-client", "arv"},
739                         {"bin/arvados-server"},
740                         // sdk/cli
741                         {"bin/arv", "arv-ruby"},
742                         {"bin/arv-tag"},
743                         // sdk/python
744                         {"lib/python/bin/arv-copy"},
745                         {"lib/python/bin/arv-federation-migrate"},
746                         {"lib/python/bin/arv-get"},
747                         {"lib/python/bin/arv-keepdocker"},
748                         {"lib/python/bin/arv-ls"},
749                         {"lib/python/bin/arv-migrate-docker19"},
750                         {"lib/python/bin/arv-normalize"},
751                         {"lib/python/bin/arv-put"},
752                         {"lib/python/bin/arv-ws"},
753                         // services/fuse
754                         {"lib/python/bin/arv-mount"},
755                 } {
756                         src := "/var/lib/arvados/" + srcdst[0]
757                         if _, err = os.Stat(src); err != nil {
758                                 return 1
759                         }
760                         dst := srcdst[len(srcdst)-1]
761                         _, dst = filepath.Split(dst)
762                         dst = "/usr/bin/" + dst
763                         err = os.Remove(dst)
764                         if err != nil && !errors.Is(err, os.ErrNotExist) {
765                                 return 1
766                         }
767                         err = os.Symlink(src, dst)
768                         if err != nil {
769                                 return 1
770                         }
771                 }
772         }
773
774         return 0
775 }
776
777 type osversion struct {
778         Debian bool
779         Ubuntu bool
780         Centos bool
781         Major  int
782 }
783
784 func identifyOS() (osversion, error) {
785         var osv osversion
786         f, err := os.Open("/etc/os-release")
787         if err != nil {
788                 return osv, err
789         }
790         defer f.Close()
791
792         kv := map[string]string{}
793         scanner := bufio.NewScanner(f)
794         for scanner.Scan() {
795                 line := strings.TrimSpace(scanner.Text())
796                 if strings.HasPrefix(line, "#") {
797                         continue
798                 }
799                 toks := strings.SplitN(line, "=", 2)
800                 if len(toks) != 2 {
801                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
802                 }
803                 k := toks[0]
804                 v := strings.Trim(toks[1], `"`)
805                 if v == toks[1] {
806                         v = strings.Trim(v, `'`)
807                 }
808                 kv[k] = v
809         }
810         if err = scanner.Err(); err != nil {
811                 return osv, err
812         }
813         switch kv["ID"] {
814         case "ubuntu":
815                 osv.Ubuntu = true
816         case "debian":
817                 osv.Debian = true
818         case "centos":
819                 osv.Centos = true
820         default:
821                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
822         }
823         vstr := kv["VERSION_ID"]
824         if i := strings.Index(vstr, "."); i > 0 {
825                 vstr = vstr[:i]
826         }
827         osv.Major, err = strconv.Atoi(vstr)
828         if err != nil {
829                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
830         }
831         return osv, nil
832 }
833
834 func waitPostgreSQLReady() error {
835         for deadline := time.Now().Add(10 * time.Second); ; {
836                 output, err := exec.Command("pg_isready").CombinedOutput()
837                 if err == nil {
838                         return nil
839                 } else if time.Now().After(deadline) {
840                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
841                 } else {
842                         time.Sleep(time.Second)
843                 }
844         }
845 }
846
847 func (inst *installCommand) runBash(script string, stdout, stderr io.Writer) error {
848         cmd := exec.Command("bash", "-")
849         if inst.EatMyData {
850                 cmd = exec.Command("eatmydata", "bash", "-")
851         }
852         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
853         cmd.Stdout = stdout
854         cmd.Stderr = stderr
855         return cmd.Run()
856 }
857
858 func prodpkgs(osv osversion) []string {
859         pkgs := []string{
860                 "ca-certificates",
861                 "curl",
862                 "fuse",
863                 "git",
864                 "gitolite3",
865                 "graphviz",
866                 "haveged",
867                 "libcurl3-gnutls",
868                 "libxslt1.1",
869                 "nginx",
870                 "python3",
871                 "sudo",
872         }
873         if osv.Debian || osv.Ubuntu {
874                 if osv.Debian && osv.Major == 8 {
875                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
876                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
877                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
878                 }
879                 return append(pkgs,
880                         "mime-support", // keep-web
881                 )
882         } else if osv.Centos {
883                 return append(pkgs,
884                         "fuse-libs", // services/fuse
885                         "mailcap",   // keep-web
886                 )
887         } else {
888                 panic("os version not supported")
889         }
890 }
891
892 func ProductionDependencies() ([]string, error) {
893         osv, err := identifyOS()
894         if err != nil {
895                 return nil, err
896         }
897         return prodpkgs(osv), nil
898 }