16306: Fix permission issues.
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         "errors"
12         "flag"
13         "fmt"
14         "io"
15         "os"
16         "os/exec"
17         "os/user"
18         "path/filepath"
19         "strconv"
20         "strings"
21         "syscall"
22         "time"
23
24         "git.arvados.org/arvados.git/lib/cmd"
25         "git.arvados.org/arvados.git/sdk/go/ctxlog"
26         "github.com/lib/pq"
27 )
28
29 var Command cmd.Handler = &installCommand{}
30
31 const devtestDatabasePassword = "insecure_arvados_test"
32
33 type installCommand struct {
34         ClusterType    string
35         SourcePath     string
36         PackageVersion string
37         EatMyData      bool
38 }
39
40 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
41         logger := ctxlog.New(stderr, "text", "info")
42         ctx := ctxlog.Context(context.Background(), logger)
43         ctx, cancel := context.WithCancel(ctx)
44         defer cancel()
45
46         var err error
47         defer func() {
48                 if err != nil {
49                         logger.WithError(err).Info("exiting")
50                 }
51         }()
52
53         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
54         flags.SetOutput(stderr)
55         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
56         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
57         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
58         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
59         flags.BoolVar(&inst.EatMyData, "eatmydata", false, "use eatmydata to speed up install")
60         err = flags.Parse(args)
61         if err == flag.ErrHelp {
62                 err = nil
63                 return 0
64         } else if err != nil {
65                 return 2
66         } else if *versionFlag {
67                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
68         } else if len(flags.Args()) > 0 {
69                 err = fmt.Errorf("unrecognized command line arguments: %v", flags.Args())
70                 return 2
71         }
72
73         var dev, test, prod, pkg bool
74         switch inst.ClusterType {
75         case "development":
76                 dev = true
77         case "test":
78                 test = true
79         case "production":
80                 prod = true
81         case "package":
82                 pkg = true
83         default:
84                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
85                 return 2
86         }
87
88         if prod {
89                 err = errors.New("production install is not yet implemented")
90                 return 1
91         }
92
93         osv, err := identifyOS()
94         if err != nil {
95                 return 1
96         }
97
98         listdir, err := os.Open("/var/lib/apt/lists")
99         if err != nil {
100                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
101         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
102                 // Special case for a base docker image where the
103                 // package cache has been deleted and all "apt-get
104                 // install" commands will fail unless we fetch repos.
105                 cmd := exec.CommandContext(ctx, "apt-get", "update")
106                 cmd.Stdout = stdout
107                 cmd.Stderr = stderr
108                 err = cmd.Run()
109                 if err != nil {
110                         return 1
111                 }
112         }
113
114         if inst.EatMyData {
115                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends", "eatmydata")
116                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
117                 cmd.Stdout = stdout
118                 cmd.Stderr = stderr
119                 err = cmd.Run()
120                 if err != nil {
121                         return 1
122                 }
123         }
124
125         pkgs := prodpkgs(osv)
126
127         if pkg {
128                 pkgs = append(pkgs,
129                         "dpkg-dev",
130                         "eatmydata", // install it for later steps, even if we're not using it now
131                         "rsync",
132                 )
133         }
134
135         if dev || test || pkg {
136                 pkgs = append(pkgs,
137                         "automake",
138                         "bison",
139                         "bsdmainutils",
140                         "build-essential",
141                         "cadaver",
142                         "curl",
143                         "cython3",
144                         "daemontools", // lib/boot uses setuidgid to drop privileges when running as root
145                         "default-jdk-headless",
146                         "default-jre-headless",
147                         "gettext",
148                         "iceweasel",
149                         "libattr1-dev",
150                         "libcrypt-ssleay-perl",
151                         "libfuse-dev",
152                         "libgnutls28-dev",
153                         "libjson-perl",
154                         "libpam-dev",
155                         "libpcre3-dev",
156                         "libpq-dev",
157                         "libreadline-dev",
158                         "libssl-dev",
159                         "libwww-perl",
160                         "libxml2-dev",
161                         "libxslt1-dev",
162                         "linkchecker",
163                         "lsof",
164                         "make",
165                         "net-tools",
166                         "pandoc",
167                         "perl-modules",
168                         "pkg-config",
169                         "postgresql",
170                         "postgresql-contrib",
171                         "python3-dev",
172                         "python3-venv",
173                         "python3-virtualenv",
174                         "r-base",
175                         "r-cran-testthat",
176                         "r-cran-devtools",
177                         "r-cran-knitr",
178                         "r-cran-markdown",
179                         "r-cran-roxygen2",
180                         "r-cran-xml",
181                         "sudo",
182                         "wget",
183                         "xvfb",
184                 )
185                 switch {
186                 case osv.Debian && osv.Major >= 10:
187                         pkgs = append(pkgs, "libcurl4")
188                 default:
189                         pkgs = append(pkgs, "libcurl3")
190                 }
191                 cmd := exec.CommandContext(ctx, "apt-get")
192                 if inst.EatMyData {
193                         cmd = exec.CommandContext(ctx, "eatmydata", "apt-get")
194                 }
195                 cmd.Args = append(cmd.Args, "install", "--yes", "--no-install-recommends")
196                 cmd.Args = append(cmd.Args, pkgs...)
197                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
198                 cmd.Stdout = stdout
199                 cmd.Stderr = stderr
200                 err = cmd.Run()
201                 if err != nil {
202                         return 1
203                 }
204         }
205
206         os.Mkdir("/var/lib/arvados", 0755)
207         os.Mkdir("/var/lib/arvados/tmp", 0700)
208         if prod || pkg {
209                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
210                 u, er := user.Lookup("www-data")
211                 if er != nil {
212                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
213                         return 1
214                 }
215                 uid, _ := strconv.Atoi(u.Uid)
216                 gid, _ := strconv.Atoi(u.Gid)
217                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
218                 if err != nil {
219                         return 1
220                 }
221         }
222         rubyversion := "2.5.7"
223         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+rubyversion)) {
224                 logger.Print("ruby " + rubyversion + " already installed")
225         } else {
226                 err = inst.runBash(`
227 tmp="$(mktemp -d)"
228 trap 'rm -r "${tmp}"' ERR EXIT
229 wget --progress=dot:giga -O- https://cache.ruby-lang.org/pub/ruby/2.5/ruby-`+rubyversion+`.tar.gz | tar -C "${tmp}" -xzf -
230 cd "${tmp}/ruby-`+rubyversion+`"
231 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
232 make -j8
233 make install
234 /var/lib/arvados/bin/gem install bundler --no-ri --no-rdoc
235 # "gem update --system" can be removed when we use ruby â‰¥2.6.3: https://bundler.io/blog/2019/05/14/solutions-for-cant-find-gem-bundler-with-executable-bundle.html
236 /var/lib/arvados/bin/gem update --system --no-ri --no-rdoc
237 `, stdout, stderr)
238                 if err != nil {
239                         return 1
240                 }
241         }
242
243         if !prod {
244                 goversion := "1.14"
245                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
246                         logger.Print("go " + goversion + " already installed")
247                 } else {
248                         err = inst.runBash(`
249 cd /tmp
250 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
251 ln -sf /var/lib/arvados/go/bin/* /usr/local/bin/
252 `, stdout, stderr)
253                         if err != nil {
254                                 return 1
255                         }
256                 }
257         }
258
259         if !prod && !pkg {
260                 pjsversion := "1.9.8"
261                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
262                         logger.Print("phantomjs " + pjsversion + " already installed")
263                 } else {
264                         err = inst.runBash(`
265 PJS=phantomjs-`+pjsversion+`-linux-x86_64
266 wget --progress=dot:giga -O- https://bitbucket.org/ariya/phantomjs/downloads/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
267 ln -sf /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
268 `, stdout, stderr)
269                         if err != nil {
270                                 return 1
271                         }
272                 }
273
274                 geckoversion := "0.24.0"
275                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
276                         logger.Print("geckodriver " + geckoversion + " already installed")
277                 } else {
278                         err = inst.runBash(`
279 GD=v`+geckoversion+`
280 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
281 ln -sf /var/lib/arvados/bin/geckodriver /usr/local/bin/
282 `, stdout, stderr)
283                         if err != nil {
284                                 return 1
285                         }
286                 }
287
288                 nodejsversion := "v8.15.1"
289                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == nodejsversion+"\n" {
290                         logger.Print("nodejs " + nodejsversion + " already installed")
291                 } else {
292                         err = inst.runBash(`
293 NJS=`+nodejsversion+`
294 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
295 ln -sf /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
296 `, stdout, stderr)
297                         if err != nil {
298                                 return 1
299                         }
300                 }
301
302                 gradleversion := "5.3.1"
303                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
304                         logger.Print("gradle " + gradleversion + " already installed")
305                 } else {
306                         err = inst.runBash(`
307 G=`+gradleversion+`
308 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
309 trap "rm ${zip}" ERR
310 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
311 unzip -o -d /var/lib/arvados ${zip}
312 ln -sf /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
313 rm ${zip}
314 `, stdout, stderr)
315                         if err != nil {
316                                 return 1
317                         }
318                 }
319
320                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
321                 // it's installed, locale -a reports it as
322                 // "en_US.utf8".
323                 wantlocale := "en_US.UTF-8"
324                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
325                         logger.Print("locale " + wantlocale + " already installed")
326                 } else {
327                         err = inst.runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
328                         if err != nil {
329                                 return 1
330                         }
331                 }
332
333                 var pgc struct {
334                         Version       string
335                         Cluster       string
336                         Port          int
337                         Status        string
338                         Owner         string
339                         DataDirectory string
340                         LogFile       string
341                 }
342                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
343                         err = fmt.Errorf("pg_lsclusters: %s", err2)
344                         return 1
345                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
346                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
347                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
348                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
349                         return 1
350                 } else if pgc.Status == "online" {
351                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
352                 } else {
353                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
354                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
355                         cmd.Stdout = stdout
356                         cmd.Stderr = stderr
357                         err = cmd.Start()
358                         if err != nil {
359                                 return 1
360                         }
361                         defer func() {
362                                 cmd.Process.Signal(syscall.SIGTERM)
363                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
364                                 cmd.Wait()
365                         }()
366                         err = waitPostgreSQLReady()
367                         if err != nil {
368                                 return 1
369                         }
370                 }
371
372                 if os.Getpid() == 1 {
373                         // We are the init process (presumably in a
374                         // docker container) so although postgresql is
375                         // installed, it's not running, and initdb
376                         // might never have been run.
377                 }
378
379                 var needcoll []string
380                 // If the en_US.UTF-8 locale wasn't installed when
381                 // postgresql initdb ran, it needs to be added
382                 // explicitly before we can use it in our test suite.
383                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
384                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
385                         cmd.Dir = "/"
386                         out, err2 := cmd.CombinedOutput()
387                         if err != nil {
388                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
389                                 return 1
390                         }
391                         if strings.Contains(string(out), "1") {
392                                 logger.Infof("postgresql supports collation %s", collname)
393                         } else {
394                                 needcoll = append(needcoll, collname)
395                         }
396                 }
397                 if len(needcoll) > 0 && os.Getpid() != 1 {
398                         // In order for the CREATE COLLATION statement
399                         // below to work, the locale must have existed
400                         // when PostgreSQL started up. If we're
401                         // running as init, we must have started
402                         // PostgreSQL ourselves after installing the
403                         // locales. Otherwise, it might need a
404                         // restart, so we attempt to restart it with
405                         // systemd.
406                         if err = inst.runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
407                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
408                         } else if err = waitPostgreSQLReady(); err != nil {
409                                 return 1
410                         }
411                 }
412                 for _, collname := range needcoll {
413                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
414                         cmd.Stdout = stdout
415                         cmd.Stderr = stderr
416                         cmd.Dir = "/"
417                         err = cmd.Run()
418                         if err != nil {
419                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
420                                 return 1
421                         }
422                 }
423
424                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
425                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
426                 cmd.Dir = "/"
427                 if err := cmd.Run(); err == nil {
428                         logger.Print("arvados role exists; superuser privileges added, password updated")
429                 } else {
430                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
431                         cmd.Dir = "/"
432                         cmd.Stdout = stdout
433                         cmd.Stderr = stderr
434                         err = cmd.Run()
435                         if err != nil {
436                                 return 1
437                         }
438                 }
439         }
440
441         if prod || pkg {
442                 // Install Rails apps to /var/lib/arvados/{railsapi,workbench1}/
443                 for dstdir, srcdir := range map[string]string{
444                         "railsapi":   "services/api",
445                         "workbench1": "apps/workbench",
446                 } {
447                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
448                         cmd := exec.Command("rsync",
449                                 "-a", "--no-owner", "--no-group", "--delete-after", "--delete-excluded",
450                                 "--exclude", "/coverage",
451                                 "--exclude", "/log",
452                                 "--exclude", "/tmp",
453                                 "--exclude", "/vendor",
454                                 "./", "/var/lib/arvados/"+dstdir+"/")
455                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
456                         cmd.Stdout = stdout
457                         cmd.Stderr = stderr
458                         err = cmd.Run()
459                         if err != nil {
460                                 return 1
461                         }
462                         for _, cmdline := range [][]string{
463                                 {"mkdir", "-p", "log", "tmp", ".bundle", "/var/www/.gem", "/var/www/.bundle", "/var/www/.passenger"},
464                                 {"touch", "log/production.log"},
465                                 {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.gem", "/var/www/.bundle", "/var/www/.passenger", "log", "tmp", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
466                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:1.16.6", "bundler:1.17.3", "bundler:2.0.2"},
467                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--deployment", "--jobs", "8", "--path", "/var/www/.gem"},
468                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
469                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
470                         } {
471                                 cmd = exec.Command(cmdline[0], cmdline[1:]...)
472                                 cmd.Dir = "/var/lib/arvados/" + dstdir
473                                 cmd.Stdout = stdout
474                                 cmd.Stderr = stderr
475                                 fmt.Fprintf(stderr, "... %s\n", cmd.Args)
476                                 err = cmd.Run()
477                                 if err != nil {
478                                         return 1
479                                 }
480                         }
481                         cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
482                         cmd.Dir = "/var/lib/arvados/" + dstdir
483                         cmd.Stdout = stdout
484                         cmd.Stderr = stderr
485                         err = cmd.Run()
486                         if err != nil && !strings.Contains(err.Error(), "exit status 2") {
487                                 // Exit code 2 indicates there were warnings (like
488                                 // "other passenger installations have been detected",
489                                 // which we can't expect to avoid) but no errors.
490                                 // Other non-zero exit codes (1, 9) indicate errors.
491                                 return 1
492                         }
493                 }
494
495                 // Install Go programs to /var/lib/arvados/bin/
496                 for _, srcdir := range []string{
497                         "cmd/arvados-client",
498                         "cmd/arvados-server",
499                         "services/arv-git-httpd",
500                         "services/crunch-dispatch-local",
501                         "services/crunch-dispatch-slurm",
502                         "services/health",
503                         "services/keep-balance",
504                         "services/keep-web",
505                         "services/keepproxy",
506                         "services/keepstore",
507                         "services/ws",
508                 } {
509                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
510                         cmd := exec.Command("go", "install", "-ldflags", "-X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+" -X main.version="+inst.PackageVersion)
511                         cmd.Env = append([]string{"GOBIN=/var/lib/arvados/bin"}, os.Environ()...)
512                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
513                         cmd.Stdout = stdout
514                         cmd.Stderr = stderr
515                         err = cmd.Run()
516                         if err != nil {
517                                 return 1
518                         }
519                 }
520
521                 // Copy assets from source tree to /var/lib/arvados/share
522                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
523                 cmd.Stdout = stdout
524                 cmd.Stderr = stderr
525                 err = cmd.Run()
526                 if err != nil {
527                         return 1
528                 }
529         }
530
531         return 0
532 }
533
534 type osversion struct {
535         Debian bool
536         Ubuntu bool
537         Centos bool
538         Major  int
539 }
540
541 func identifyOS() (osversion, error) {
542         var osv osversion
543         f, err := os.Open("/etc/os-release")
544         if err != nil {
545                 return osv, err
546         }
547         defer f.Close()
548
549         kv := map[string]string{}
550         scanner := bufio.NewScanner(f)
551         for scanner.Scan() {
552                 line := strings.TrimSpace(scanner.Text())
553                 if strings.HasPrefix(line, "#") {
554                         continue
555                 }
556                 toks := strings.SplitN(line, "=", 2)
557                 if len(toks) != 2 {
558                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
559                 }
560                 k := toks[0]
561                 v := strings.Trim(toks[1], `"`)
562                 if v == toks[1] {
563                         v = strings.Trim(v, `'`)
564                 }
565                 kv[k] = v
566         }
567         if err = scanner.Err(); err != nil {
568                 return osv, err
569         }
570         switch kv["ID"] {
571         case "ubuntu":
572                 osv.Ubuntu = true
573         case "debian":
574                 osv.Debian = true
575         case "centos":
576                 osv.Centos = true
577         default:
578                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
579         }
580         vstr := kv["VERSION_ID"]
581         if i := strings.Index(vstr, "."); i > 0 {
582                 vstr = vstr[:i]
583         }
584         osv.Major, err = strconv.Atoi(vstr)
585         if err != nil {
586                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
587         }
588         return osv, nil
589 }
590
591 func waitPostgreSQLReady() error {
592         for deadline := time.Now().Add(10 * time.Second); ; {
593                 output, err := exec.Command("pg_isready").CombinedOutput()
594                 if err == nil {
595                         return nil
596                 } else if time.Now().After(deadline) {
597                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
598                 } else {
599                         time.Sleep(time.Second)
600                 }
601         }
602 }
603
604 func (inst *installCommand) runBash(script string, stdout, stderr io.Writer) error {
605         cmd := exec.Command("bash", "-")
606         if inst.EatMyData {
607                 cmd = exec.Command("eatmydata", "bash", "-")
608         }
609         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
610         cmd.Stdout = stdout
611         cmd.Stderr = stderr
612         return cmd.Run()
613 }
614
615 func prodpkgs(osv osversion) []string {
616         pkgs := []string{
617                 "ca-certificates",
618                 "curl",
619                 "fuse",
620                 "git",
621                 "gitolite3",
622                 "graphviz",
623                 "haveged",
624                 "libcurl3-gnutls",
625                 "libxslt1.1",
626                 "nginx",
627                 "python",
628                 "sudo",
629         }
630         if osv.Debian || osv.Ubuntu {
631                 if osv.Debian && osv.Major == 8 {
632                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
633                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
634                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
635                 }
636                 return append(pkgs,
637                         "g++",
638                         "libcurl4-openssl-dev", // services/api
639                         "libpq-dev",
640                         "libpython2.7", // services/fuse
641                         "mime-support", // keep-web
642                         "zlib1g-dev",   // services/api
643                 )
644         } else if osv.Centos {
645                 return append(pkgs,
646                         "fuse-libs", // services/fuse
647                         "gcc",
648                         "gcc-c++",
649                         "libcurl-devel",    // services/api
650                         "mailcap",          // keep-web
651                         "postgresql-devel", // services/api
652                 )
653         } else {
654                 panic("os version not supported")
655         }
656 }
657
658 func ProductionDependencies() ([]string, error) {
659         osv, err := identifyOS()
660         if err != nil {
661                 return nil, err
662         }
663         return prodpkgs(osv), nil
664 }