998da1200c10e3ce74f6c6a41da1120e48a8dbe4
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         _ "embed"
12         "errors"
13         "flag"
14         "fmt"
15         "io"
16         "os"
17         "os/exec"
18         "os/user"
19         "path/filepath"
20         "regexp"
21         "runtime"
22         "strconv"
23         "strings"
24         "syscall"
25         "time"
26
27         "git.arvados.org/arvados.git/lib/cmd"
28         "git.arvados.org/arvados.git/sdk/go/ctxlog"
29         "github.com/lib/pq"
30 )
31
32 var Command cmd.Handler = &installCommand{}
33
34 const goversion = "1.20.6"
35
36 const (
37         defaultRubyVersion      = "3.2.2"
38         defaultBundlerVersion   = "2.2.19"
39         singularityversion      = "3.10.4"
40         pjsversion              = "1.9.8"
41         geckoversion            = "0.24.0"
42         gradleversion           = "5.3.1"
43         nodejsversion           = "v12.22.12"
44         devtestDatabasePassword = "insecure_arvados_test"
45 )
46
47 //go:embed arvados.service
48 var arvadosServiceFile []byte
49
50 type installCommand struct {
51         ClusterType    string
52         SourcePath     string
53         Commit         string
54         PackageVersion string
55         RubyVersion    string
56         BundlerVersion string
57         EatMyData      bool
58 }
59
60 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
61         logger := ctxlog.New(stderr, "text", "info")
62         ctx := ctxlog.Context(context.Background(), logger)
63         ctx, cancel := context.WithCancel(ctx)
64         defer cancel()
65
66         var err error
67         defer func() {
68                 if err != nil {
69                         logger.WithError(err).Info("exiting")
70                 }
71         }()
72
73         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
74         flags.SetOutput(stderr)
75         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
76         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
77         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
78         flags.StringVar(&inst.Commit, "commit", "", "source commit `hash` to embed (blank means use 'git log' or all-zero placeholder)")
79         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
80         flags.StringVar(&inst.RubyVersion, "ruby-version", defaultRubyVersion, "Ruby `version` to install (do not override in production mode)")
81         flags.StringVar(&inst.BundlerVersion, "bundler-version", defaultBundlerVersion, "Bundler `version` to install (do not override in production mode)")
82         flags.BoolVar(&inst.EatMyData, "eatmydata", false, "use eatmydata to speed up install")
83
84         if ok, code := cmd.ParseFlags(flags, prog, args, "", stderr); !ok {
85                 return code
86         } else if *versionFlag {
87                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
88         }
89
90         if inst.Commit == "" {
91                 if commit, err := exec.Command("env", "-C", inst.SourcePath, "git", "log", "-n1", "--format=%H").CombinedOutput(); err == nil {
92                         inst.Commit = strings.TrimSpace(string(commit))
93                 } else {
94                         inst.Commit = "0000000000000000000000000000000000000000"
95                 }
96         }
97
98         var dev, test, prod, pkg bool
99         switch inst.ClusterType {
100         case "development":
101                 dev = true
102         case "test":
103                 test = true
104         case "production":
105                 prod = true
106         case "package":
107                 pkg = true
108         default:
109                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
110                 return 2
111         }
112
113         if prod {
114                 err = errors.New("production install is not yet implemented")
115                 return 1
116         }
117
118         if ok, _ := regexp.MatchString(`^\d\.\d+\.\d+$`, inst.RubyVersion); !ok {
119                 fmt.Fprintf(stderr, "invalid argument %q for -ruby-version\n", inst.RubyVersion)
120                 return 64
121         }
122         if ok, _ := regexp.MatchString(`^\d`, inst.BundlerVersion); !ok {
123                 fmt.Fprintf(stderr, "invalid argument %q for -bundler-version\n", inst.BundlerVersion)
124                 return 64
125         }
126
127         osv, err := identifyOS()
128         if err != nil {
129                 return 1
130         }
131
132         listdir, err := os.Open("/var/lib/apt/lists")
133         if err != nil {
134                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
135         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
136                 // Special case for a base docker image where the
137                 // package cache has been deleted and all "apt-get
138                 // install" commands will fail unless we fetch repos.
139                 cmd := exec.CommandContext(ctx, "apt-get", "update")
140                 cmd.Stdout = stdout
141                 cmd.Stderr = stderr
142                 err = cmd.Run()
143                 if err != nil {
144                         return 1
145                 }
146         }
147
148         if inst.EatMyData {
149                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends", "eatmydata")
150                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
151                 cmd.Stdout = stdout
152                 cmd.Stderr = stderr
153                 err = cmd.Run()
154                 if err != nil {
155                         return 1
156                 }
157         }
158
159         pkgs := prodpkgs(osv)
160
161         if pkg {
162                 pkgs = append(pkgs,
163                         "dpkg-dev",
164                         "eatmydata", // install it for later steps, even if we're not using it now
165                 )
166         }
167
168         if dev || test || pkg {
169                 pkgs = append(pkgs,
170                         "automake",
171                         "bison",
172                         "bsdmainutils",
173                         "build-essential",
174                         "cadaver",
175                         "curl",
176                         "cython3",
177                         "default-jdk-headless",
178                         "default-jre-headless",
179                         "gettext",
180                         "libattr1-dev",
181                         "libffi-dev",
182                         "libfuse-dev",
183                         "libgbm1", // cypress / workbench2 tests
184                         "libgnutls28-dev",
185                         "libpam-dev",
186                         "libpcre3-dev",
187                         "libpq-dev",
188                         "libreadline-dev",
189                         "libssl-dev",
190                         "libxml2-dev",
191                         "libxslt1-dev",
192                         "libyaml-dev",
193                         "linkchecker",
194                         "lsof",
195                         "make",
196                         "net-tools",
197                         "pandoc",
198                         "pkg-config",
199                         "postgresql",
200                         "postgresql-contrib",
201                         "python3-dev",
202                         "python3-venv",
203                         "python3-virtualenv",
204                         "r-base",
205                         "r-cran-testthat",
206                         "r-cran-devtools",
207                         "r-cran-knitr",
208                         "r-cran-markdown",
209                         "r-cran-roxygen2",
210                         "r-cran-xml",
211                         "rsync",
212                         "sudo",
213                         "uuid-dev",
214                         "wget",
215                         "xvfb",
216                         "zlib1g-dev", // services/api
217                 )
218                 if test {
219                         if osv.Debian && osv.Major <= 10 {
220                                 pkgs = append(pkgs, "iceweasel")
221                         } else if osv.Debian && osv.Major >= 11 {
222                                 pkgs = append(pkgs, "firefox-esr")
223                         } else {
224                                 pkgs = append(pkgs, "firefox")
225                         }
226                 }
227                 if dev || test {
228                         pkgs = append(pkgs,
229                                 "libglib2.0-dev", // singularity (conmon)
230                                 "libseccomp-dev", // singularity (seccomp)
231                                 "squashfs-tools", // singularity
232                                 "gnupg")          // docker install recipe
233                 }
234                 switch {
235                 case osv.Debian && osv.Major >= 10,
236                         osv.Ubuntu && osv.Major >= 22:
237                         pkgs = append(pkgs, "g++", "libcurl4", "libcurl4-openssl-dev")
238                 case osv.Debian || osv.Ubuntu:
239                         pkgs = append(pkgs, "g++", "libcurl3", "libcurl3-openssl-dev")
240                 case osv.Centos:
241                         pkgs = append(pkgs, "gcc", "gcc-c++", "libcurl-devel", "postgresql-devel")
242                 }
243                 cmd := exec.CommandContext(ctx, "apt-get")
244                 if inst.EatMyData {
245                         cmd = exec.CommandContext(ctx, "eatmydata", "apt-get")
246                 }
247                 cmd.Args = append(cmd.Args, "install", "--yes", "--no-install-recommends")
248                 cmd.Args = append(cmd.Args, pkgs...)
249                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
250                 cmd.Stdout = stdout
251                 cmd.Stderr = stderr
252                 err = cmd.Run()
253                 if err != nil {
254                         return 1
255                 }
256         }
257
258         if dev || test {
259                 if havedockerversion, err2 := exec.Command("docker", "--version").CombinedOutput(); err2 == nil {
260                         logger.Printf("%s installed, assuming that version is ok", bytes.TrimSuffix(havedockerversion, []byte("\n")))
261                 } else if osv.Debian {
262                         var codename string
263                         switch osv.Major {
264                         case 10:
265                                 codename = "buster"
266                         case 11:
267                                 codename = "bullseye"
268                         case 12:
269                                 codename = "bookworm"
270                         default:
271                                 err = fmt.Errorf("don't know how to install docker-ce for debian %d", osv.Major)
272                                 return 1
273                         }
274                         err = inst.runBash(`
275 rm -f /usr/share/keyrings/docker-archive-keyring.gpg
276 curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
277 echo 'deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian/ `+codename+` stable' | \
278     tee /etc/apt/sources.list.d/docker.list
279 apt-get update
280 DEBIAN_FRONTEND=noninteractive apt-get --yes --no-install-recommends install docker-ce
281 `, stdout, stderr)
282                         if err != nil {
283                                 return 1
284                         }
285                 } else {
286                         err = fmt.Errorf("don't know how to install docker for osversion %v", osv)
287                         return 1
288                 }
289
290                 err = inst.runBash(`
291 key=fs.inotify.max_user_watches
292 min=524288
293 if [[ "$(sysctl --values "${key}")" -lt "${min}" ]]; then
294     sysctl "${key}=${min}"
295     # writing sysctl worked, so we should make it permanent
296     echo "${key}=${min}" | tee -a /etc/sysctl.conf
297     sysctl -p
298 fi
299 `, stdout, stderr)
300                 if err != nil {
301                         err = fmt.Errorf("couldn't set fs.inotify.max_user_watches value. (Is this a docker container? Fix this on the docker host by adding fs.inotify.max_user_watches=524288 to /etc/sysctl.conf and running `sysctl -p`)")
302                         return 1
303                 }
304         }
305
306         os.Mkdir("/var/lib/arvados", 0755)
307         os.Mkdir("/var/lib/arvados/tmp", 0700)
308         if prod || pkg {
309                 u, er := user.Lookup("www-data")
310                 if er != nil {
311                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
312                         return 1
313                 }
314                 uid, _ := strconv.Atoi(u.Uid)
315                 gid, _ := strconv.Atoi(u.Gid)
316                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
317                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
318                 if err != nil {
319                         return 1
320                 }
321         }
322         rubyminorversion := inst.RubyVersion[:strings.LastIndex(inst.RubyVersion, ".")]
323         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+inst.RubyVersion)) {
324                 logger.Print("ruby " + inst.RubyVersion + " already installed")
325         } else {
326                 err = inst.runBash(`
327 rubyversion="`+inst.RubyVersion+`"
328 rubyminorversion="`+rubyminorversion+`"
329 tmp="$(mktemp -d)"
330 trap 'rm -r "${tmp}"' ERR EXIT
331 wget --progress=dot:giga -O- "https://cache.ruby-lang.org/pub/ruby/$rubyminorversion/ruby-$rubyversion.tar.gz" | tar -C "${tmp}" -xzf -
332 cd "${tmp}/ruby-$rubyversion"
333 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
334 make -j8
335 rm -f /var/lib/arvados/bin/erb
336 make install
337 if [[ "$rubyversion" > "3" ]]; then
338   /var/lib/arvados/bin/gem update --no-document --system 3.4.21
339 fi
340 /var/lib/arvados/bin/gem install bundler --no-document
341 `, stdout, stderr)
342                 if err != nil {
343                         return 1
344                 }
345         }
346
347         if !prod {
348                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
349                         logger.Print("go " + goversion + " already installed")
350                 } else {
351                         err = inst.runBash(`
352 cd /tmp
353 rm -rf /var/lib/arvados/go/
354 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
355 ln -sfv /var/lib/arvados/go/bin/* /usr/local/bin/
356 `, stdout, stderr)
357                         if err != nil {
358                                 return 1
359                         }
360                 }
361         }
362
363         if !prod && !pkg {
364                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
365                         logger.Print("phantomjs " + pjsversion + " already installed")
366                 } else {
367                         err = inst.runBash(`
368 PJS=phantomjs-`+pjsversion+`-linux-x86_64
369 wget --progress=dot:giga -O- https://cache.arvados.org/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
370 ln -sfv /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
371 `, stdout, stderr)
372                         if err != nil {
373                                 return 1
374                         }
375                 }
376
377                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
378                         logger.Print("geckodriver " + geckoversion + " already installed")
379                 } else {
380                         err = inst.runBash(`
381 GD=v`+geckoversion+`
382 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
383 ln -sfv /var/lib/arvados/bin/geckodriver /usr/local/bin/
384 `, stdout, stderr)
385                         if err != nil {
386                                 return 1
387                         }
388                 }
389
390                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
391                         logger.Print("gradle " + gradleversion + " already installed")
392                 } else {
393                         err = inst.runBash(`
394 G=`+gradleversion+`
395 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
396 trap "rm ${zip}" ERR
397 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
398 unzip -o -d /var/lib/arvados ${zip}
399 ln -sfv /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
400 rm ${zip}
401 `, stdout, stderr)
402                         if err != nil {
403                                 return 1
404                         }
405                 }
406
407                 if havesingularityversion, err := exec.Command("/var/lib/arvados/bin/singularity", "--version").CombinedOutput(); err == nil && strings.Contains(string(havesingularityversion), singularityversion) {
408                         logger.Print("singularity " + singularityversion + " already installed")
409                 } else if dev || test {
410                         err = inst.runBash(`
411 S=`+singularityversion+`
412 tmp=/var/lib/arvados/tmp/singularity
413 trap "rm -r ${tmp}" ERR EXIT
414 cd /var/lib/arvados/tmp
415 git clone --recurse-submodules https://github.com/sylabs/singularity
416 cd singularity
417 git checkout v${S}
418 ./mconfig --prefix=/var/lib/arvados
419 make -C ./builddir
420 make -C ./builddir install
421 `, stdout, stderr)
422                         if err != nil {
423                                 return 1
424                         }
425                 }
426
427                 err = inst.runBash(`
428 install /usr/bin/nsenter /var/lib/arvados/bin/nsenter
429 setcap "cap_sys_admin+pei cap_sys_chroot+pei" /var/lib/arvados/bin/nsenter
430 `, stdout, stderr)
431                 if err != nil {
432                         return 1
433                 }
434
435                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
436                 // it's installed, locale -a reports it as
437                 // "en_US.utf8".
438                 wantlocale := "en_US.UTF-8"
439                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
440                         logger.Print("locale " + wantlocale + " already installed")
441                 } else {
442                         err = inst.runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
443                         if err != nil {
444                                 return 1
445                         }
446                 }
447
448                 var pgc struct {
449                         Version       string
450                         Cluster       string
451                         Port          int
452                         Status        string
453                         Owner         string
454                         DataDirectory string
455                         LogFile       string
456                 }
457                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
458                         err = fmt.Errorf("pg_lsclusters: %s", err2)
459                         return 1
460                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
461                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
462                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
463                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
464                         return 1
465                 } else if pgc.Status == "online" {
466                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
467                 } else {
468                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
469                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
470                         cmd.Stdout = stdout
471                         cmd.Stderr = stderr
472                         err = cmd.Start()
473                         if err != nil {
474                                 return 1
475                         }
476                         defer func() {
477                                 cmd.Process.Signal(syscall.SIGTERM)
478                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
479                                 cmd.Wait()
480                         }()
481                         err = waitPostgreSQLReady()
482                         if err != nil {
483                                 return 1
484                         }
485                 }
486
487                 if os.Getpid() == 1 {
488                         // We are the init process (presumably in a
489                         // docker container) so although postgresql is
490                         // installed, it's not running, and initdb
491                         // might never have been run.
492                 }
493
494                 var needcoll []string
495                 // If the en_US.UTF-8 locale wasn't installed when
496                 // postgresql initdb ran, it needs to be added
497                 // explicitly before we can use it in our test suite.
498                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
499                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
500                         cmd.Dir = "/"
501                         out, err2 := cmd.CombinedOutput()
502                         if err != nil {
503                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
504                                 return 1
505                         }
506                         if strings.Contains(string(out), "1") {
507                                 logger.Infof("postgresql supports collation %s", collname)
508                         } else {
509                                 needcoll = append(needcoll, collname)
510                         }
511                 }
512                 if len(needcoll) > 0 && os.Getpid() != 1 {
513                         // In order for the CREATE COLLATION statement
514                         // below to work, the locale must have existed
515                         // when PostgreSQL started up. If we're
516                         // running as init, we must have started
517                         // PostgreSQL ourselves after installing the
518                         // locales. Otherwise, it might need a
519                         // restart, so we attempt to restart it with
520                         // systemd.
521                         if err = inst.runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
522                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
523                         } else if err = waitPostgreSQLReady(); err != nil {
524                                 return 1
525                         }
526                 }
527                 for _, collname := range needcoll {
528                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
529                         cmd.Stdout = stdout
530                         cmd.Stderr = stderr
531                         cmd.Dir = "/"
532                         err = cmd.Run()
533                         if err != nil {
534                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
535                                 return 1
536                         }
537                 }
538
539                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
540                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
541                 cmd.Dir = "/"
542                 if err := cmd.Run(); err == nil {
543                         logger.Print("arvados role exists; superuser privileges added, password updated")
544                 } else {
545                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
546                         cmd.Dir = "/"
547                         cmd.Stdout = stdout
548                         cmd.Stderr = stderr
549                         err = cmd.Run()
550                         if err != nil {
551                                 return 1
552                         }
553                 }
554         }
555
556         if !prod {
557                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == nodejsversion+"\n" {
558                         logger.Print("nodejs " + nodejsversion + " already installed")
559                 } else {
560                         err = inst.runBash(`
561 NJS=`+nodejsversion+`
562 rm -rf /var/lib/arvados/node-*-linux-x64
563 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
564 ln -sfv /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
565 `, stdout, stderr)
566                         if err != nil {
567                                 return 1
568                         }
569                 }
570
571                 if haveyarnversion, err := exec.Command("/usr/local/bin/yarn", "--version").CombinedOutput(); err == nil && len(haveyarnversion) > 0 {
572                         logger.Print("yarn " + strings.TrimSpace(string(haveyarnversion)) + " already installed")
573                 } else {
574                         err = inst.runBash(`
575 npm install -g yarn
576 ln -sfv /var/lib/arvados/node-`+nodejsversion+`-linux-x64/bin/{yarn,yarnpkg} /usr/local/bin/
577 `, stdout, stderr)
578                         if err != nil {
579                                 return 1
580                         }
581                 }
582         }
583
584         if prod || pkg {
585                 // Install Go programs to /var/lib/arvados/bin/
586                 for _, srcdir := range []string{
587                         "cmd/arvados-client",
588                         "cmd/arvados-server",
589                 } {
590                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
591                         // -buildvcs=false here avoids a fatal "error
592                         // obtaining VCS status" when git refuses to
593                         // run (for example) as root in a docker
594                         // container using a non-root-owned git tree
595                         // mounted from the host -- as in
596                         // "arvados-package build".
597                         cmd := exec.Command("go", "install", "-buildvcs=false",
598                                 "-ldflags", "-s -w"+
599                                         " -X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+
600                                         " -X git.arvados.org/arvados.git/lib/cmd.commit="+inst.Commit)
601                         cmd.Env = append(cmd.Env, os.Environ()...)
602                         cmd.Env = append(cmd.Env, "GOBIN=/var/lib/arvados/bin")
603                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
604                         cmd.Stdout = stdout
605                         cmd.Stderr = stderr
606                         err = cmd.Run()
607                         if err != nil {
608                                 return 1
609                         }
610                 }
611
612                 // Copy assets from source tree to /var/lib/arvados/share
613                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
614                 cmd.Stdout = stdout
615                 cmd.Stderr = stderr
616                 err = cmd.Run()
617                 if err != nil {
618                         return 1
619                 }
620
621                 // Install python SDK and arv-mount in
622                 // /var/lib/arvados/lib/python.
623                 //
624                 // setup.py writes a file in the source directory in
625                 // order to include the version number in the package
626                 // itself.  We don't want to write to the source tree
627                 // (in "arvados-package" context it's mounted
628                 // readonly) so we run setup.py in a temporary copy of
629                 // the source dir.
630                 if err = inst.runBash(`
631 v=/var/lib/arvados/lib/python
632 tmp=/var/lib/arvados/tmp/python
633 python3 -m venv "$v"
634 . "$v/bin/activate"
635 pip3 install --no-cache-dir 'setuptools>=68' 'pip>=20'
636 export ARVADOS_BUILDING_VERSION="`+inst.PackageVersion+`"
637 for src in "`+inst.SourcePath+`/sdk/python" "`+inst.SourcePath+`/services/fuse"; do
638   rsync -a --delete-after "$src/" "$tmp/"
639   env -C "$tmp" python3 setup.py build
640   pip3 install "$tmp"
641   rm -rf "$tmp"
642 done
643 `, stdout, stderr); err != nil {
644                         return 1
645                 }
646
647                 // Install RailsAPI to /var/lib/arvados/railsapi/
648                 fmt.Fprintln(stderr, "building railsapi...")
649                 cmd = exec.Command("rsync",
650                         "-a", "--no-owner", "--no-group", "--delete-after", "--delete-excluded",
651                         "--exclude", "/coverage",
652                         "--exclude", "/log",
653                         "--exclude", "/node_modules",
654                         "--exclude", "/tmp",
655                         "--exclude", "/public/assets",
656                         "--exclude", "/vendor",
657                         "--exclude", "/config/environments",
658                         "./", "/var/lib/arvados/railsapi/")
659                 cmd.Dir = filepath.Join(inst.SourcePath, "services", "api")
660                 cmd.Stdout = stdout
661                 cmd.Stderr = stderr
662                 err = cmd.Run()
663                 if err != nil {
664                         return 1
665                 }
666                 for _, cmdline := range [][]string{
667                         {"mkdir", "-p", "log", "public/assets", "tmp", "vendor", ".bundle", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger"},
668                         {"touch", "log/production.log"},
669                         {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger", "log", "tmp", "vendor", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
670                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:" + inst.BundlerVersion},
671                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "deployment", "true"},
672                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "path", "/var/www/.gem"},
673                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "without", "development test diagnostics performance"},
674                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--jobs", fmt.Sprintf("%d", runtime.NumCPU())},
675
676                         {"chown", "www-data:www-data", ".", "public/assets"},
677                         // {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "system", "true"},
678                         {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "npm:install"},
679                         {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "assets:precompile"},
680                         {"chown", "root:root", "."},
681                         {"chown", "-R", "root:root", "public/assets", "vendor"},
682
683                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
684                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
685                 } {
686                         if cmdline[len(cmdline)-2] == "rake" {
687                                 continue
688                         }
689                         cmd = exec.Command(cmdline[0], cmdline[1:]...)
690                         cmd.Dir = "/var/lib/arvados/railsapi"
691                         cmd.Stdout = stdout
692                         cmd.Stderr = stderr
693                         fmt.Fprintf(stderr, "... %s\n", cmd.Args)
694                         err = cmd.Run()
695                         if err != nil {
696                                 return 1
697                         }
698                 }
699                 cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
700                 cmd.Dir = "/var/lib/arvados/railsapi"
701                 cmd.Stdout = stdout
702                 cmd.Stderr = stderr
703                 err = cmd.Run()
704                 if err != nil && !strings.Contains(err.Error(), "exit status 2") {
705                         // Exit code 2 indicates there were warnings (like
706                         // "other passenger installations have been detected",
707                         // which we can't expect to avoid) but no errors.
708                         // Other non-zero exit codes (1, 9) indicate errors.
709                         return 1
710                 }
711
712                 // Install workbench2 app to
713                 // /var/lib/arvados/workbench2/.
714                 //
715                 // We copy the source tree from the (possibly
716                 // readonly) source tree into a temp dir because `yarn
717                 // build` writes to {source-tree}/build/. When we
718                 // upgrade to react-scripts >= 4.0.2 we may be able to
719                 // build from the source dir and write directly to the
720                 // final destination (using
721                 // YARN_INSTALL_STATE_PATH=/dev/null
722                 // BUILD_PATH=/var/lib/arvados/workbench2) instead of
723                 // using two rsync steps here.
724                 if err = inst.runBash(`
725 src="`+inst.SourcePath+`/services/workbench2"
726 tmp=/var/lib/arvados/tmp/workbench2
727 trap "rm -r ${tmp}" ERR EXIT
728 dst=/var/lib/arvados/workbench2
729 rsync -a --delete-after "$src/" "$tmp/"
730 env -C "$tmp" VERSION="`+inst.PackageVersion+`" BUILD_NUMBER=1 GIT_COMMIT="`+inst.Commit[:9]+`" yarn build
731 rsync -a --delete-after "$tmp/build/" "$dst/"
732 `, stdout, stderr); err != nil {
733                         return 1
734                 }
735
736                 // Install arvados-cli gem (binaries go in
737                 // /var/lib/arvados/bin)
738                 if err = inst.runBash(`
739 /var/lib/arvados/bin/gem install --conservative --no-document arvados-cli
740 `, stdout, stderr); err != nil {
741                         return 1
742                 }
743
744                 err = os.WriteFile("/lib/systemd/system/arvados.service", arvadosServiceFile, 0777)
745                 if err != nil {
746                         return 1
747                 }
748                 if prod {
749                         // (fpm will do this for us in the pkg case)
750                         // This is equivalent to "systemd enable", but
751                         // does not depend on the systemctl program
752                         // being available:
753                         symlink := "/etc/systemd/system/multi-user.target.wants/arvados.service"
754                         err = os.Remove(symlink)
755                         if err != nil && !errors.Is(err, os.ErrNotExist) {
756                                 return 1
757                         }
758                         err = os.Symlink("/lib/systemd/system/arvados.service", symlink)
759                         if err != nil {
760                                 return 1
761                         }
762                 }
763
764                 // Add symlinks in /usr/bin for user-facing programs
765                 for _, srcdst := range [][]string{
766                         // go
767                         {"bin/arvados-client"},
768                         {"bin/arvados-client", "arv"},
769                         {"bin/arvados-server"},
770                         // sdk/cli
771                         {"bin/arv", "arv-ruby"},
772                         {"bin/arv-tag"},
773                         // sdk/python
774                         {"lib/python/bin/arv-copy"},
775                         {"lib/python/bin/arv-federation-migrate"},
776                         {"lib/python/bin/arv-get"},
777                         {"lib/python/bin/arv-keepdocker"},
778                         {"lib/python/bin/arv-ls"},
779                         {"lib/python/bin/arv-migrate-docker19"},
780                         {"lib/python/bin/arv-normalize"},
781                         {"lib/python/bin/arv-put"},
782                         {"lib/python/bin/arv-ws"},
783                         // services/fuse
784                         {"lib/python/bin/arv-mount"},
785                 } {
786                         src := "/var/lib/arvados/" + srcdst[0]
787                         if _, err = os.Stat(src); err != nil {
788                                 return 1
789                         }
790                         dst := srcdst[len(srcdst)-1]
791                         _, dst = filepath.Split(dst)
792                         dst = "/usr/bin/" + dst
793                         err = os.Remove(dst)
794                         if err != nil && !errors.Is(err, os.ErrNotExist) {
795                                 return 1
796                         }
797                         err = os.Symlink(src, dst)
798                         if err != nil {
799                                 return 1
800                         }
801                 }
802         }
803
804         return 0
805 }
806
807 type osversion struct {
808         Debian bool
809         Ubuntu bool
810         Centos bool
811         Major  int
812 }
813
814 func identifyOS() (osversion, error) {
815         var osv osversion
816         f, err := os.Open("/etc/os-release")
817         if err != nil {
818                 return osv, err
819         }
820         defer f.Close()
821
822         kv := map[string]string{}
823         scanner := bufio.NewScanner(f)
824         for scanner.Scan() {
825                 line := strings.TrimSpace(scanner.Text())
826                 if strings.HasPrefix(line, "#") {
827                         continue
828                 }
829                 toks := strings.SplitN(line, "=", 2)
830                 if len(toks) != 2 {
831                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
832                 }
833                 k := toks[0]
834                 v := strings.Trim(toks[1], `"`)
835                 if v == toks[1] {
836                         v = strings.Trim(v, `'`)
837                 }
838                 kv[k] = v
839         }
840         if err = scanner.Err(); err != nil {
841                 return osv, err
842         }
843         switch kv["ID"] {
844         case "ubuntu":
845                 osv.Ubuntu = true
846         case "debian":
847                 osv.Debian = true
848         case "centos":
849                 osv.Centos = true
850         default:
851                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
852         }
853         vstr := kv["VERSION_ID"]
854         if i := strings.Index(vstr, "."); i > 0 {
855                 vstr = vstr[:i]
856         }
857         osv.Major, err = strconv.Atoi(vstr)
858         if err != nil {
859                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
860         }
861         return osv, nil
862 }
863
864 func waitPostgreSQLReady() error {
865         for deadline := time.Now().Add(10 * time.Second); ; {
866                 output, err := exec.Command("pg_isready").CombinedOutput()
867                 if err == nil {
868                         return nil
869                 } else if time.Now().After(deadline) {
870                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
871                 } else {
872                         time.Sleep(time.Second)
873                 }
874         }
875 }
876
877 func (inst *installCommand) runBash(script string, stdout, stderr io.Writer) error {
878         cmd := exec.Command("bash", "-")
879         if inst.EatMyData {
880                 cmd = exec.Command("eatmydata", "bash", "-")
881         }
882         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
883         cmd.Stdout = stdout
884         cmd.Stderr = stderr
885         return cmd.Run()
886 }
887
888 func prodpkgs(osv osversion) []string {
889         pkgs := []string{
890                 "ca-certificates",
891                 "curl",
892                 "fuse",
893                 "git",
894                 "gitolite3",
895                 "graphviz",
896                 "haveged",
897                 "libcurl3-gnutls",
898                 "libxslt1.1",
899                 "nginx",
900                 "python3",
901                 "sudo",
902         }
903         if osv.Debian || osv.Ubuntu {
904                 if osv.Debian && osv.Major == 8 {
905                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
906                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
907                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
908                 }
909                 return append(pkgs,
910                         "mime-support", // keep-web
911                 )
912         } else if osv.Centos {
913                 return append(pkgs,
914                         "fuse-libs", // services/fuse
915                         "mailcap",   // keep-web
916                 )
917         } else {
918                 panic("os version not supported")
919         }
920 }
921
922 func ProductionDependencies() ([]string, error) {
923         osv, err := identifyOS()
924         if err != nil {
925                 return nil, err
926         }
927         return prodpkgs(osv), nil
928 }