6c43637eb6cb33ac6eca1ef25db7dd2ceb7198b0
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         _ "embed"
12         "errors"
13         "flag"
14         "fmt"
15         "io"
16         "os"
17         "os/exec"
18         "os/user"
19         "path/filepath"
20         "strconv"
21         "strings"
22         "syscall"
23         "time"
24
25         "git.arvados.org/arvados.git/lib/cmd"
26         "git.arvados.org/arvados.git/sdk/go/ctxlog"
27         "github.com/lib/pq"
28 )
29
30 var Command cmd.Handler = &installCommand{}
31
32 const goversion = "1.17.7"
33
34 const (
35         rubyversion             = "2.7.5"
36         bundlerversion          = "2.2.19"
37         singularityversion      = "3.9.9"
38         pjsversion              = "1.9.8"
39         geckoversion            = "0.24.0"
40         gradleversion           = "5.3.1"
41         nodejsversion           = "v12.22.11"
42         devtestDatabasePassword = "insecure_arvados_test"
43         workbench2version       = "5e020488f67b5bc919796e0dc8b0b9f3b3ff23b0"
44 )
45
46 //go:embed arvados.service
47 var arvadosServiceFile []byte
48
49 type installCommand struct {
50         ClusterType    string
51         SourcePath     string
52         PackageVersion string
53         EatMyData      bool
54 }
55
56 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
57         logger := ctxlog.New(stderr, "text", "info")
58         ctx := ctxlog.Context(context.Background(), logger)
59         ctx, cancel := context.WithCancel(ctx)
60         defer cancel()
61
62         var err error
63         defer func() {
64                 if err != nil {
65                         logger.WithError(err).Info("exiting")
66                 }
67         }()
68
69         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
70         flags.SetOutput(stderr)
71         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
72         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
73         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
74         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
75         flags.BoolVar(&inst.EatMyData, "eatmydata", false, "use eatmydata to speed up install")
76
77         if ok, code := cmd.ParseFlags(flags, prog, args, "", stderr); !ok {
78                 return code
79         } else if *versionFlag {
80                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
81         }
82
83         var dev, test, prod, pkg bool
84         switch inst.ClusterType {
85         case "development":
86                 dev = true
87         case "test":
88                 test = true
89         case "production":
90                 prod = true
91         case "package":
92                 pkg = true
93         default:
94                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
95                 return 2
96         }
97
98         if prod {
99                 err = errors.New("production install is not yet implemented")
100                 return 1
101         }
102
103         osv, err := identifyOS()
104         if err != nil {
105                 return 1
106         }
107
108         listdir, err := os.Open("/var/lib/apt/lists")
109         if err != nil {
110                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
111         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
112                 // Special case for a base docker image where the
113                 // package cache has been deleted and all "apt-get
114                 // install" commands will fail unless we fetch repos.
115                 cmd := exec.CommandContext(ctx, "apt-get", "update")
116                 cmd.Stdout = stdout
117                 cmd.Stderr = stderr
118                 err = cmd.Run()
119                 if err != nil {
120                         return 1
121                 }
122         }
123
124         if inst.EatMyData {
125                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends", "eatmydata")
126                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
127                 cmd.Stdout = stdout
128                 cmd.Stderr = stderr
129                 err = cmd.Run()
130                 if err != nil {
131                         return 1
132                 }
133         }
134
135         pkgs := prodpkgs(osv)
136
137         if pkg {
138                 pkgs = append(pkgs,
139                         "dpkg-dev",
140                         "eatmydata", // install it for later steps, even if we're not using it now
141                 )
142         }
143
144         if dev || test || pkg {
145                 pkgs = append(pkgs,
146                         "automake",
147                         "bison",
148                         "bsdmainutils",
149                         "build-essential",
150                         "cadaver",
151                         "curl",
152                         "cython3",
153                         "default-jdk-headless",
154                         "default-jre-headless",
155                         "gettext",
156                         "libattr1-dev",
157                         "libcrypt-ssleay-perl",
158                         "libfuse-dev",
159                         "libgnutls28-dev",
160                         "libjson-perl",
161                         "libpam-dev",
162                         "libpcre3-dev",
163                         "libpq-dev",
164                         "libreadline-dev",
165                         "libssl-dev",
166                         "libwww-perl",
167                         "libxml2-dev",
168                         "libxslt1-dev",
169                         "linkchecker",
170                         "lsof",
171                         "make",
172                         "net-tools",
173                         "pandoc",
174                         "pkg-config",
175                         "postgresql",
176                         "postgresql-contrib",
177                         "python3-dev",
178                         "python3-venv",
179                         "python3-virtualenv",
180                         "r-base",
181                         "r-cran-testthat",
182                         "r-cran-devtools",
183                         "r-cran-knitr",
184                         "r-cran-markdown",
185                         "r-cran-roxygen2",
186                         "r-cran-xml",
187                         "rsync",
188                         "sudo",
189                         "uuid-dev",
190                         "wget",
191                         "xvfb",
192                 )
193                 if test {
194                         if osv.Debian && osv.Major <= 10 {
195                                 pkgs = append(pkgs, "iceweasel")
196                         } else {
197                                 pkgs = append(pkgs, "firefox")
198                         }
199                 }
200                 if dev || test {
201                         pkgs = append(pkgs, "squashfs-tools") // for singularity
202                         pkgs = append(pkgs, "gnupg")          // for docker install recipe
203                 }
204                 switch {
205                 case osv.Debian && osv.Major >= 11:
206                         pkgs = append(pkgs, "libcurl4", "perl-modules-5.32")
207                 case osv.Debian && osv.Major >= 10:
208                         pkgs = append(pkgs, "libcurl4", "perl-modules")
209                 default:
210                         pkgs = append(pkgs, "libcurl3", "perl-modules")
211                 }
212                 cmd := exec.CommandContext(ctx, "apt-get")
213                 if inst.EatMyData {
214                         cmd = exec.CommandContext(ctx, "eatmydata", "apt-get")
215                 }
216                 cmd.Args = append(cmd.Args, "install", "--yes", "--no-install-recommends")
217                 cmd.Args = append(cmd.Args, pkgs...)
218                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
219                 cmd.Stdout = stdout
220                 cmd.Stderr = stderr
221                 err = cmd.Run()
222                 if err != nil {
223                         return 1
224                 }
225         }
226
227         if dev || test {
228                 if havedockerversion, err := exec.Command("docker", "--version").CombinedOutput(); err == nil {
229                         logger.Printf("%s installed, assuming that version is ok", bytes.TrimSuffix(havedockerversion, []byte("\n")))
230                 } else if osv.Debian {
231                         var codename string
232                         switch osv.Major {
233                         case 10:
234                                 codename = "buster"
235                         case 11:
236                                 codename = "bullseye"
237                         default:
238                                 err = fmt.Errorf("don't know how to install docker-ce for debian %d", osv.Major)
239                                 return 1
240                         }
241                         err = inst.runBash(`
242 rm -f /usr/share/keyrings/docker-archive-keyring.gpg
243 curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
244 echo 'deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian/ `+codename+` stable' | \
245     tee /etc/apt/sources.list.d/docker.list
246 apt-get update
247 DEBIAN_FRONTEND=noninteractive apt-get --yes --no-install-recommends install docker-ce
248 `, stdout, stderr)
249                         if err != nil {
250                                 return 1
251                         }
252                 } else {
253                         err = fmt.Errorf("don't know how to install docker for osversion %v", osv)
254                         return 1
255                 }
256         }
257
258         os.Mkdir("/var/lib/arvados", 0755)
259         os.Mkdir("/var/lib/arvados/tmp", 0700)
260         if prod || pkg {
261                 u, er := user.Lookup("www-data")
262                 if er != nil {
263                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
264                         return 1
265                 }
266                 uid, _ := strconv.Atoi(u.Uid)
267                 gid, _ := strconv.Atoi(u.Gid)
268                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
269                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
270                 if err != nil {
271                         return 1
272                 }
273         }
274         rubymajorversion := rubyversion[:strings.LastIndex(rubyversion, ".")]
275         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+rubyversion)) {
276                 logger.Print("ruby " + rubyversion + " already installed")
277         } else {
278                 err = inst.runBash(`
279 tmp="$(mktemp -d)"
280 trap 'rm -r "${tmp}"' ERR EXIT
281 wget --progress=dot:giga -O- https://cache.ruby-lang.org/pub/ruby/`+rubymajorversion+`/ruby-`+rubyversion+`.tar.gz | tar -C "${tmp}" -xzf -
282 cd "${tmp}/ruby-`+rubyversion+`"
283 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
284 make -j8
285 make install
286 /var/lib/arvados/bin/gem install bundler --no-document
287 `, stdout, stderr)
288                 if err != nil {
289                         return 1
290                 }
291         }
292
293         if !prod {
294                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
295                         logger.Print("go " + goversion + " already installed")
296                 } else {
297                         err = inst.runBash(`
298 cd /tmp
299 rm -rf /var/lib/arvados/go/
300 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
301 ln -sfv /var/lib/arvados/go/bin/* /usr/local/bin/
302 `, stdout, stderr)
303                         if err != nil {
304                                 return 1
305                         }
306                 }
307         }
308
309         if !prod && !pkg {
310                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
311                         logger.Print("phantomjs " + pjsversion + " already installed")
312                 } else {
313                         err = inst.runBash(`
314 PJS=phantomjs-`+pjsversion+`-linux-x86_64
315 wget --progress=dot:giga -O- https://cache.arvados.org/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
316 ln -sfv /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
317 `, stdout, stderr)
318                         if err != nil {
319                                 return 1
320                         }
321                 }
322
323                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
324                         logger.Print("geckodriver " + geckoversion + " already installed")
325                 } else {
326                         err = inst.runBash(`
327 GD=v`+geckoversion+`
328 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
329 ln -sfv /var/lib/arvados/bin/geckodriver /usr/local/bin/
330 `, stdout, stderr)
331                         if err != nil {
332                                 return 1
333                         }
334                 }
335
336                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
337                         logger.Print("gradle " + gradleversion + " already installed")
338                 } else {
339                         err = inst.runBash(`
340 G=`+gradleversion+`
341 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
342 trap "rm ${zip}" ERR
343 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
344 unzip -o -d /var/lib/arvados ${zip}
345 ln -sfv /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
346 rm ${zip}
347 `, stdout, stderr)
348                         if err != nil {
349                                 return 1
350                         }
351                 }
352
353                 if havesingularityversion, err := exec.Command("/var/lib/arvados/bin/singularity", "--version").CombinedOutput(); err == nil && strings.Contains(string(havesingularityversion), singularityversion) {
354                         logger.Print("singularity " + singularityversion + " already installed")
355                 } else if dev || test {
356                         err = inst.runBash(`
357 S=`+singularityversion+`
358 tmp=/var/lib/arvados/tmp/singularity
359 trap "rm -r ${tmp}" ERR EXIT
360 cd /var/lib/arvados/tmp
361 git clone https://github.com/sylabs/singularity
362 cd singularity
363 git checkout v${S}
364 ./mconfig --prefix=/var/lib/arvados
365 make -C ./builddir
366 make -C ./builddir install
367 `, stdout, stderr)
368                         if err != nil {
369                                 return 1
370                         }
371                 }
372
373                 err = inst.runBash(`
374 install /usr/bin/nsenter /var/lib/arvados/bin/nsenter
375 setcap "cap_sys_admin+pei cap_sys_chroot+pei" /var/lib/arvados/bin/nsenter
376 `, stdout, stderr)
377                 if err != nil {
378                         return 1
379                 }
380
381                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
382                 // it's installed, locale -a reports it as
383                 // "en_US.utf8".
384                 wantlocale := "en_US.UTF-8"
385                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
386                         logger.Print("locale " + wantlocale + " already installed")
387                 } else {
388                         err = inst.runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
389                         if err != nil {
390                                 return 1
391                         }
392                 }
393
394                 var pgc struct {
395                         Version       string
396                         Cluster       string
397                         Port          int
398                         Status        string
399                         Owner         string
400                         DataDirectory string
401                         LogFile       string
402                 }
403                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
404                         err = fmt.Errorf("pg_lsclusters: %s", err2)
405                         return 1
406                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
407                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
408                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
409                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
410                         return 1
411                 } else if pgc.Status == "online" {
412                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
413                 } else {
414                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
415                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
416                         cmd.Stdout = stdout
417                         cmd.Stderr = stderr
418                         err = cmd.Start()
419                         if err != nil {
420                                 return 1
421                         }
422                         defer func() {
423                                 cmd.Process.Signal(syscall.SIGTERM)
424                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
425                                 cmd.Wait()
426                         }()
427                         err = waitPostgreSQLReady()
428                         if err != nil {
429                                 return 1
430                         }
431                 }
432
433                 if os.Getpid() == 1 {
434                         // We are the init process (presumably in a
435                         // docker container) so although postgresql is
436                         // installed, it's not running, and initdb
437                         // might never have been run.
438                 }
439
440                 var needcoll []string
441                 // If the en_US.UTF-8 locale wasn't installed when
442                 // postgresql initdb ran, it needs to be added
443                 // explicitly before we can use it in our test suite.
444                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
445                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
446                         cmd.Dir = "/"
447                         out, err2 := cmd.CombinedOutput()
448                         if err != nil {
449                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
450                                 return 1
451                         }
452                         if strings.Contains(string(out), "1") {
453                                 logger.Infof("postgresql supports collation %s", collname)
454                         } else {
455                                 needcoll = append(needcoll, collname)
456                         }
457                 }
458                 if len(needcoll) > 0 && os.Getpid() != 1 {
459                         // In order for the CREATE COLLATION statement
460                         // below to work, the locale must have existed
461                         // when PostgreSQL started up. If we're
462                         // running as init, we must have started
463                         // PostgreSQL ourselves after installing the
464                         // locales. Otherwise, it might need a
465                         // restart, so we attempt to restart it with
466                         // systemd.
467                         if err = inst.runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
468                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
469                         } else if err = waitPostgreSQLReady(); err != nil {
470                                 return 1
471                         }
472                 }
473                 for _, collname := range needcoll {
474                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
475                         cmd.Stdout = stdout
476                         cmd.Stderr = stderr
477                         cmd.Dir = "/"
478                         err = cmd.Run()
479                         if err != nil {
480                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
481                                 return 1
482                         }
483                 }
484
485                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
486                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
487                 cmd.Dir = "/"
488                 if err := cmd.Run(); err == nil {
489                         logger.Print("arvados role exists; superuser privileges added, password updated")
490                 } else {
491                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
492                         cmd.Dir = "/"
493                         cmd.Stdout = stdout
494                         cmd.Stderr = stderr
495                         err = cmd.Run()
496                         if err != nil {
497                                 return 1
498                         }
499                 }
500         }
501
502         if !prod {
503                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == nodejsversion+"\n" {
504                         logger.Print("nodejs " + nodejsversion + " already installed")
505                 } else {
506                         err = inst.runBash(`
507 NJS=`+nodejsversion+`
508 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
509 ln -sfv /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
510 `, stdout, stderr)
511                         if err != nil {
512                                 return 1
513                         }
514                 }
515
516                 if haveyarnversion, err := exec.Command("/usr/local/bin/yarn", "--version").CombinedOutput(); err == nil && len(haveyarnversion) > 0 {
517                         logger.Print("yarn " + strings.TrimSpace(string(haveyarnversion)) + " already installed")
518                 } else {
519                         err = inst.runBash(`
520 npm install -g yarn
521 ln -sfv /var/lib/arvados/node-`+nodejsversion+`-linux-x64/bin/{yarn,yarnpkg} /usr/local/bin/
522 `, stdout, stderr)
523                         if err != nil {
524                                 return 1
525                         }
526                 }
527
528                 if havewb2version, err := exec.Command("git", "--git-dir=/var/lib/arvados/arvados-workbench2/.git", "log", "-n1", "--format=%H").CombinedOutput(); err == nil && string(havewb2version) == workbench2version+"\n" {
529                         logger.Print("workbench2 repo is already at " + workbench2version)
530                 } else {
531                         err = inst.runBash(`
532 V=`+workbench2version+`
533 cd /var/lib/arvados
534 if [[ ! -e arvados-workbench2 ]]; then
535   git clone https://git.arvados.org/arvados-workbench2.git
536   cd arvados-workbench2
537   git checkout $V
538 else
539   cd arvados-workbench2
540   if ! git checkout $V; then
541     git fetch
542     git checkout yarn.lock
543     git checkout $V
544   fi
545 fi
546 rm -rf build
547 `, stdout, stderr)
548                         if err != nil {
549                                 return 1
550                         }
551                 }
552
553                 if err = inst.runBash(`
554 cd /var/lib/arvados/arvados-workbench2
555 yarn install
556 `, stdout, stderr); err != nil {
557                         return 1
558                 }
559         }
560
561         if prod || pkg {
562                 // Install Go programs to /var/lib/arvados/bin/
563                 for _, srcdir := range []string{
564                         "cmd/arvados-client",
565                         "cmd/arvados-server",
566                         "services/crunch-dispatch-local",
567                         "services/crunch-dispatch-slurm",
568                         "services/health",
569                         "services/keep-balance",
570                         "services/keepstore",
571                         "services/ws",
572                 } {
573                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
574                         cmd := exec.Command("go", "install", "-ldflags", "-X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+" -X main.version="+inst.PackageVersion+" -s -w")
575                         cmd.Env = append(cmd.Env, os.Environ()...)
576                         cmd.Env = append(cmd.Env, "GOBIN=/var/lib/arvados/bin")
577                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
578                         cmd.Stdout = stdout
579                         cmd.Stderr = stderr
580                         err = cmd.Run()
581                         if err != nil {
582                                 return 1
583                         }
584                 }
585
586                 // Symlink user-facing Go programs /usr/bin/x ->
587                 // /var/lib/arvados/bin/x
588                 for _, prog := range []string{"arvados-client", "arvados-server"} {
589                         err = os.Remove("/usr/bin/" + prog)
590                         if err != nil && !errors.Is(err, os.ErrNotExist) {
591                                 return 1
592                         }
593                         err = os.Symlink("/var/lib/arvados/bin/"+prog, "/usr/bin/"+prog)
594                         if err != nil {
595                                 return 1
596                         }
597                 }
598
599                 // Copy assets from source tree to /var/lib/arvados/share
600                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
601                 cmd.Stdout = stdout
602                 cmd.Stderr = stderr
603                 err = cmd.Run()
604                 if err != nil {
605                         return 1
606                 }
607
608                 // Install Rails apps to /var/lib/arvados/{railsapi,workbench1}/
609                 for dstdir, srcdir := range map[string]string{
610                         "railsapi":   "services/api",
611                         "workbench1": "apps/workbench",
612                 } {
613                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
614                         cmd := exec.Command("rsync",
615                                 "-a", "--no-owner", "--no-group", "--delete-after", "--delete-excluded",
616                                 "--exclude", "/coverage",
617                                 "--exclude", "/log",
618                                 "--exclude", "/node_modules",
619                                 "--exclude", "/tmp",
620                                 "--exclude", "/public/assets",
621                                 "--exclude", "/vendor",
622                                 "--exclude", "/config/environments",
623                                 "./", "/var/lib/arvados/"+dstdir+"/")
624                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
625                         cmd.Stdout = stdout
626                         cmd.Stderr = stderr
627                         err = cmd.Run()
628                         if err != nil {
629                                 return 1
630                         }
631                         for _, cmdline := range [][]string{
632                                 {"mkdir", "-p", "log", "public/assets", "tmp", "vendor", ".bundle", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger"},
633                                 {"touch", "log/production.log"},
634                                 {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger", "log", "tmp", "vendor", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
635                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:" + bundlerversion},
636                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--deployment", "--jobs", "8", "--path", "/var/www/.gem", "--without", "development test diagnostics performance"},
637
638                                 {"chown", "www-data:www-data", ".", "public/assets"},
639                                 // {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "system", "true"},
640                                 {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "/var/lib/arvados/bin/bundle", "exec", "rake", "npm:install"},
641                                 {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "/var/lib/arvados/bin/bundle", "exec", "rake", "assets:precompile"},
642                                 {"chown", "root:root", "."},
643                                 {"chown", "-R", "root:root", "public/assets", "vendor"},
644
645                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
646                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
647                         } {
648                                 if cmdline[len(cmdline)-2] == "rake" && dstdir != "workbench1" {
649                                         continue
650                                 }
651                                 cmd = exec.Command(cmdline[0], cmdline[1:]...)
652                                 cmd.Dir = "/var/lib/arvados/" + dstdir
653                                 cmd.Stdout = stdout
654                                 cmd.Stderr = stderr
655                                 fmt.Fprintf(stderr, "... %s\n", cmd.Args)
656                                 err = cmd.Run()
657                                 if err != nil {
658                                         return 1
659                                 }
660                         }
661                         cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
662                         cmd.Dir = "/var/lib/arvados/" + dstdir
663                         cmd.Stdout = stdout
664                         cmd.Stderr = stderr
665                         err = cmd.Run()
666                         if err != nil && !strings.Contains(err.Error(), "exit status 2") {
667                                 // Exit code 2 indicates there were warnings (like
668                                 // "other passenger installations have been detected",
669                                 // which we can't expect to avoid) but no errors.
670                                 // Other non-zero exit codes (1, 9) indicate errors.
671                                 return 1
672                         }
673                 }
674
675                 // Install workbench2 app to /var/lib/arvados/workbench2/
676                 if err = inst.runBash(`
677 cd /var/lib/arvados/arvados-workbench2
678 VERSION="`+inst.PackageVersion+`" BUILD_NUMBER=1 GIT_COMMIT="`+workbench2version[:9]+`" yarn build
679 rsync -a --delete-after build/ /var/lib/arvados/workbench2/
680 `, stdout, stderr); err != nil {
681                         return 1
682                 }
683
684                 err = os.WriteFile("/lib/systemd/system/arvados.service", arvadosServiceFile, 0777)
685                 if err != nil {
686                         return 1
687                 }
688                 // This is equivalent to "systemd enable", but does
689                 // not depend on the systemctl program being
690                 // available.
691                 symlink := "/etc/systemd/system/multi-user.target.wants/arvados.service"
692                 err = os.Remove(symlink)
693                 if err != nil && !errors.Is(err, os.ErrNotExist) {
694                         return 1
695                 }
696                 err = os.Symlink("/lib/systemd/system/arvados.service", symlink)
697                 if err != nil {
698                         return 1
699                 }
700         }
701
702         return 0
703 }
704
705 type osversion struct {
706         Debian bool
707         Ubuntu bool
708         Centos bool
709         Major  int
710 }
711
712 func identifyOS() (osversion, error) {
713         var osv osversion
714         f, err := os.Open("/etc/os-release")
715         if err != nil {
716                 return osv, err
717         }
718         defer f.Close()
719
720         kv := map[string]string{}
721         scanner := bufio.NewScanner(f)
722         for scanner.Scan() {
723                 line := strings.TrimSpace(scanner.Text())
724                 if strings.HasPrefix(line, "#") {
725                         continue
726                 }
727                 toks := strings.SplitN(line, "=", 2)
728                 if len(toks) != 2 {
729                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
730                 }
731                 k := toks[0]
732                 v := strings.Trim(toks[1], `"`)
733                 if v == toks[1] {
734                         v = strings.Trim(v, `'`)
735                 }
736                 kv[k] = v
737         }
738         if err = scanner.Err(); err != nil {
739                 return osv, err
740         }
741         switch kv["ID"] {
742         case "ubuntu":
743                 osv.Ubuntu = true
744         case "debian":
745                 osv.Debian = true
746         case "centos":
747                 osv.Centos = true
748         default:
749                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
750         }
751         vstr := kv["VERSION_ID"]
752         if i := strings.Index(vstr, "."); i > 0 {
753                 vstr = vstr[:i]
754         }
755         osv.Major, err = strconv.Atoi(vstr)
756         if err != nil {
757                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
758         }
759         return osv, nil
760 }
761
762 func waitPostgreSQLReady() error {
763         for deadline := time.Now().Add(10 * time.Second); ; {
764                 output, err := exec.Command("pg_isready").CombinedOutput()
765                 if err == nil {
766                         return nil
767                 } else if time.Now().After(deadline) {
768                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
769                 } else {
770                         time.Sleep(time.Second)
771                 }
772         }
773 }
774
775 func (inst *installCommand) runBash(script string, stdout, stderr io.Writer) error {
776         cmd := exec.Command("bash", "-")
777         if inst.EatMyData {
778                 cmd = exec.Command("eatmydata", "bash", "-")
779         }
780         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
781         cmd.Stdout = stdout
782         cmd.Stderr = stderr
783         return cmd.Run()
784 }
785
786 func prodpkgs(osv osversion) []string {
787         pkgs := []string{
788                 "ca-certificates",
789                 "curl",
790                 "fuse",
791                 "git",
792                 "gitolite3",
793                 "graphviz",
794                 "haveged",
795                 "libcurl3-gnutls",
796                 "libxslt1.1",
797                 "nginx",
798                 "python",
799                 "sudo",
800         }
801         if osv.Debian || osv.Ubuntu {
802                 if osv.Debian && osv.Major == 8 {
803                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
804                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
805                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
806                 }
807                 return append(pkgs,
808                         "g++",
809                         "libcurl4-openssl-dev", // services/api
810                         "libpq-dev",
811                         "libpython2.7", // services/fuse
812                         "mime-support", // keep-web
813                         "zlib1g-dev",   // services/api
814                 )
815         } else if osv.Centos {
816                 return append(pkgs,
817                         "fuse-libs", // services/fuse
818                         "gcc",
819                         "gcc-c++",
820                         "libcurl-devel",    // services/api
821                         "mailcap",          // keep-web
822                         "postgresql-devel", // services/api
823                 )
824         } else {
825                 panic("os version not supported")
826         }
827 }
828
829 func ProductionDependencies() ([]string, error) {
830         osv, err := identifyOS()
831         if err != nil {
832                 return nil, err
833         }
834         return prodpkgs(osv), nil
835 }