9f4af1317ff695fb9955429278b8efbf81f201fc
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         _ "embed"
12         "errors"
13         "flag"
14         "fmt"
15         "io"
16         "os"
17         "os/exec"
18         "os/user"
19         "path/filepath"
20         "regexp"
21         "runtime"
22         "strconv"
23         "strings"
24         "syscall"
25         "time"
26
27         "git.arvados.org/arvados.git/lib/cmd"
28         "git.arvados.org/arvados.git/sdk/go/ctxlog"
29         "github.com/lib/pq"
30 )
31
32 var Command cmd.Handler = &installCommand{}
33
34 const goversion = "1.20.6"
35
36 const (
37         defaultRubyVersion      = "3.2.2"
38         bundlerversion          = "2.2.19"
39         singularityversion      = "3.10.4"
40         pjsversion              = "1.9.8"
41         geckoversion            = "0.24.0"
42         gradleversion           = "5.3.1"
43         nodejsversion           = "v12.22.12"
44         devtestDatabasePassword = "insecure_arvados_test"
45 )
46
47 //go:embed arvados.service
48 var arvadosServiceFile []byte
49
50 type installCommand struct {
51         ClusterType    string
52         SourcePath     string
53         Commit         string
54         PackageVersion string
55         RubyVersion    string
56         EatMyData      bool
57 }
58
59 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
60         logger := ctxlog.New(stderr, "text", "info")
61         ctx := ctxlog.Context(context.Background(), logger)
62         ctx, cancel := context.WithCancel(ctx)
63         defer cancel()
64
65         var err error
66         defer func() {
67                 if err != nil {
68                         logger.WithError(err).Info("exiting")
69                 }
70         }()
71
72         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
73         flags.SetOutput(stderr)
74         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
75         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
76         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
77         flags.StringVar(&inst.Commit, "commit", "", "source commit `hash` to embed (blank means use 'git log' or all-zero placeholder)")
78         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
79         flags.StringVar(&inst.RubyVersion, "ruby-version", defaultRubyVersion, "Ruby `version` to install (do not override in production mode)")
80         flags.BoolVar(&inst.EatMyData, "eatmydata", false, "use eatmydata to speed up install")
81
82         if ok, code := cmd.ParseFlags(flags, prog, args, "", stderr); !ok {
83                 return code
84         } else if *versionFlag {
85                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
86         }
87
88         if inst.Commit == "" {
89                 if commit, err := exec.Command("env", "-C", inst.SourcePath, "git", "log", "-n1", "--format=%H").CombinedOutput(); err == nil {
90                         inst.Commit = strings.TrimSpace(string(commit))
91                 } else {
92                         inst.Commit = "0000000000000000000000000000000000000000"
93                 }
94         }
95
96         var dev, test, prod, pkg bool
97         switch inst.ClusterType {
98         case "development":
99                 dev = true
100         case "test":
101                 test = true
102         case "production":
103                 prod = true
104         case "package":
105                 pkg = true
106         default:
107                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
108                 return 2
109         }
110
111         if prod {
112                 err = errors.New("production install is not yet implemented")
113                 return 1
114         }
115
116         if ok, _ := regexp.MatchString(`^\d\.\d+\.\d+$`, inst.RubyVersion); !ok {
117                 fmt.Fprintf(stderr, "invalid argument %q for -ruby-version\n", inst.RubyVersion)
118                 return 64
119         }
120
121         osv, err := identifyOS()
122         if err != nil {
123                 return 1
124         }
125
126         listdir, err := os.Open("/var/lib/apt/lists")
127         if err != nil {
128                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
129         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
130                 // Special case for a base docker image where the
131                 // package cache has been deleted and all "apt-get
132                 // install" commands will fail unless we fetch repos.
133                 cmd := exec.CommandContext(ctx, "apt-get", "update")
134                 cmd.Stdout = stdout
135                 cmd.Stderr = stderr
136                 err = cmd.Run()
137                 if err != nil {
138                         return 1
139                 }
140         }
141
142         if inst.EatMyData {
143                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends", "eatmydata")
144                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
145                 cmd.Stdout = stdout
146                 cmd.Stderr = stderr
147                 err = cmd.Run()
148                 if err != nil {
149                         return 1
150                 }
151         }
152
153         pkgs := prodpkgs(osv)
154
155         if pkg {
156                 pkgs = append(pkgs,
157                         "dpkg-dev",
158                         "eatmydata", // install it for later steps, even if we're not using it now
159                 )
160         }
161
162         if dev || test || pkg {
163                 pkgs = append(pkgs,
164                         "automake",
165                         "bison",
166                         "bsdmainutils",
167                         "build-essential",
168                         "cadaver",
169                         "curl",
170                         "cython3",
171                         "default-jdk-headless",
172                         "default-jre-headless",
173                         "gettext",
174                         "libattr1-dev",
175                         "libffi-dev",
176                         "libfuse-dev",
177                         "libgbm1", // cypress / workbench2 tests
178                         "libgnutls28-dev",
179                         "libpam-dev",
180                         "libpcre3-dev",
181                         "libpq-dev",
182                         "libreadline-dev",
183                         "libssl-dev",
184                         "libxml2-dev",
185                         "libxslt1-dev",
186                         "libyaml-dev",
187                         "linkchecker",
188                         "lsof",
189                         "make",
190                         "net-tools",
191                         "pandoc",
192                         "pkg-config",
193                         "postgresql",
194                         "postgresql-contrib",
195                         "python3-dev",
196                         "python3-venv",
197                         "python3-virtualenv",
198                         "r-base",
199                         "r-cran-testthat",
200                         "r-cran-devtools",
201                         "r-cran-knitr",
202                         "r-cran-markdown",
203                         "r-cran-roxygen2",
204                         "r-cran-xml",
205                         "rsync",
206                         "sudo",
207                         "uuid-dev",
208                         "wget",
209                         "xvfb",
210                         "zlib1g-dev", // services/api
211                 )
212                 if test {
213                         if osv.Debian && osv.Major <= 10 {
214                                 pkgs = append(pkgs, "iceweasel")
215                         } else if osv.Debian && osv.Major >= 11 {
216                                 pkgs = append(pkgs, "firefox-esr")
217                         } else {
218                                 pkgs = append(pkgs, "firefox")
219                         }
220                 }
221                 if dev || test {
222                         pkgs = append(pkgs,
223                                 "libglib2.0-dev", // singularity (conmon)
224                                 "libseccomp-dev", // singularity (seccomp)
225                                 "squashfs-tools", // singularity
226                                 "gnupg")          // docker install recipe
227                 }
228                 switch {
229                 case osv.Debian && osv.Major >= 10,
230                         osv.Ubuntu && osv.Major >= 22:
231                         pkgs = append(pkgs, "g++", "libcurl4", "libcurl4-openssl-dev")
232                 case osv.Debian || osv.Ubuntu:
233                         pkgs = append(pkgs, "g++", "libcurl3", "libcurl3-openssl-dev")
234                 case osv.Centos:
235                         pkgs = append(pkgs, "gcc", "gcc-c++", "libcurl-devel", "postgresql-devel")
236                 }
237                 cmd := exec.CommandContext(ctx, "apt-get")
238                 if inst.EatMyData {
239                         cmd = exec.CommandContext(ctx, "eatmydata", "apt-get")
240                 }
241                 cmd.Args = append(cmd.Args, "install", "--yes", "--no-install-recommends")
242                 cmd.Args = append(cmd.Args, pkgs...)
243                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
244                 cmd.Stdout = stdout
245                 cmd.Stderr = stderr
246                 err = cmd.Run()
247                 if err != nil {
248                         return 1
249                 }
250         }
251
252         if dev || test {
253                 if havedockerversion, err2 := exec.Command("docker", "--version").CombinedOutput(); err2 == nil {
254                         logger.Printf("%s installed, assuming that version is ok", bytes.TrimSuffix(havedockerversion, []byte("\n")))
255                 } else if osv.Debian {
256                         var codename string
257                         switch osv.Major {
258                         case 10:
259                                 codename = "buster"
260                         case 11:
261                                 codename = "bullseye"
262                         case 12:
263                                 codename = "bookworm"
264                         default:
265                                 err = fmt.Errorf("don't know how to install docker-ce for debian %d", osv.Major)
266                                 return 1
267                         }
268                         err = inst.runBash(`
269 rm -f /usr/share/keyrings/docker-archive-keyring.gpg
270 curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
271 echo 'deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian/ `+codename+` stable' | \
272     tee /etc/apt/sources.list.d/docker.list
273 apt-get update
274 DEBIAN_FRONTEND=noninteractive apt-get --yes --no-install-recommends install docker-ce
275 `, stdout, stderr)
276                         if err != nil {
277                                 return 1
278                         }
279                 } else {
280                         err = fmt.Errorf("don't know how to install docker for osversion %v", osv)
281                         return 1
282                 }
283
284                 err = inst.runBash(`
285 key=fs.inotify.max_user_watches
286 min=524288
287 if [[ "$(sysctl --values "${key}")" -lt "${min}" ]]; then
288     sysctl "${key}=${min}"
289     # writing sysctl worked, so we should make it permanent
290     echo "${key}=${min}" | tee -a /etc/sysctl.conf
291     sysctl -p
292 fi
293 `, stdout, stderr)
294                 if err != nil {
295                         err = fmt.Errorf("couldn't set fs.inotify.max_user_watches value. (Is this a docker container? Fix this on the docker host by adding fs.inotify.max_user_watches=524288 to /etc/sysctl.conf and running `sysctl -p`)")
296                         return 1
297                 }
298         }
299
300         os.Mkdir("/var/lib/arvados", 0755)
301         os.Mkdir("/var/lib/arvados/tmp", 0700)
302         if prod || pkg {
303                 u, er := user.Lookup("www-data")
304                 if er != nil {
305                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
306                         return 1
307                 }
308                 uid, _ := strconv.Atoi(u.Uid)
309                 gid, _ := strconv.Atoi(u.Gid)
310                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
311                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
312                 if err != nil {
313                         return 1
314                 }
315         }
316         rubyminorversion := inst.RubyVersion[:strings.LastIndex(inst.RubyVersion, ".")]
317         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+inst.RubyVersion)) {
318                 logger.Print("ruby " + inst.RubyVersion + " already installed")
319         } else {
320                 err = inst.runBash(`
321 rubyversion="`+inst.RubyVersion+`"
322 rubyminorversion="`+rubyminorversion+`"
323 tmp="$(mktemp -d)"
324 trap 'rm -r "${tmp}"' ERR EXIT
325 wget --progress=dot:giga -O- "https://cache.ruby-lang.org/pub/ruby/$rubyminorversion/ruby-$rubyversion.tar.gz" | tar -C "${tmp}" -xzf -
326 cd "${tmp}/ruby-$rubyversion"
327 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
328 make -j8
329 rm -f /var/lib/arvados/bin/erb
330 make install
331 if [[ "$rubyversion" > "3" ]]; then
332   /var/lib/arvados/bin/gem update --no-document --system 3.4.21
333 fi
334 /var/lib/arvados/bin/gem install bundler --no-document
335 `, stdout, stderr)
336                 if err != nil {
337                         return 1
338                 }
339         }
340
341         if !prod {
342                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
343                         logger.Print("go " + goversion + " already installed")
344                 } else {
345                         err = inst.runBash(`
346 cd /tmp
347 rm -rf /var/lib/arvados/go/
348 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
349 ln -sfv /var/lib/arvados/go/bin/* /usr/local/bin/
350 `, stdout, stderr)
351                         if err != nil {
352                                 return 1
353                         }
354                 }
355         }
356
357         if !prod && !pkg {
358                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
359                         logger.Print("phantomjs " + pjsversion + " already installed")
360                 } else {
361                         err = inst.runBash(`
362 PJS=phantomjs-`+pjsversion+`-linux-x86_64
363 wget --progress=dot:giga -O- https://cache.arvados.org/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
364 ln -sfv /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
365 `, stdout, stderr)
366                         if err != nil {
367                                 return 1
368                         }
369                 }
370
371                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
372                         logger.Print("geckodriver " + geckoversion + " already installed")
373                 } else {
374                         err = inst.runBash(`
375 GD=v`+geckoversion+`
376 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
377 ln -sfv /var/lib/arvados/bin/geckodriver /usr/local/bin/
378 `, stdout, stderr)
379                         if err != nil {
380                                 return 1
381                         }
382                 }
383
384                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
385                         logger.Print("gradle " + gradleversion + " already installed")
386                 } else {
387                         err = inst.runBash(`
388 G=`+gradleversion+`
389 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
390 trap "rm ${zip}" ERR
391 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
392 unzip -o -d /var/lib/arvados ${zip}
393 ln -sfv /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
394 rm ${zip}
395 `, stdout, stderr)
396                         if err != nil {
397                                 return 1
398                         }
399                 }
400
401                 if havesingularityversion, err := exec.Command("/var/lib/arvados/bin/singularity", "--version").CombinedOutput(); err == nil && strings.Contains(string(havesingularityversion), singularityversion) {
402                         logger.Print("singularity " + singularityversion + " already installed")
403                 } else if dev || test {
404                         err = inst.runBash(`
405 S=`+singularityversion+`
406 tmp=/var/lib/arvados/tmp/singularity
407 trap "rm -r ${tmp}" ERR EXIT
408 cd /var/lib/arvados/tmp
409 git clone --recurse-submodules https://github.com/sylabs/singularity
410 cd singularity
411 git checkout v${S}
412 ./mconfig --prefix=/var/lib/arvados
413 make -C ./builddir
414 make -C ./builddir install
415 `, stdout, stderr)
416                         if err != nil {
417                                 return 1
418                         }
419                 }
420
421                 err = inst.runBash(`
422 install /usr/bin/nsenter /var/lib/arvados/bin/nsenter
423 setcap "cap_sys_admin+pei cap_sys_chroot+pei" /var/lib/arvados/bin/nsenter
424 `, stdout, stderr)
425                 if err != nil {
426                         return 1
427                 }
428
429                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
430                 // it's installed, locale -a reports it as
431                 // "en_US.utf8".
432                 wantlocale := "en_US.UTF-8"
433                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
434                         logger.Print("locale " + wantlocale + " already installed")
435                 } else {
436                         err = inst.runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
437                         if err != nil {
438                                 return 1
439                         }
440                 }
441
442                 var pgc struct {
443                         Version       string
444                         Cluster       string
445                         Port          int
446                         Status        string
447                         Owner         string
448                         DataDirectory string
449                         LogFile       string
450                 }
451                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
452                         err = fmt.Errorf("pg_lsclusters: %s", err2)
453                         return 1
454                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
455                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
456                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
457                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
458                         return 1
459                 } else if pgc.Status == "online" {
460                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
461                 } else {
462                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
463                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
464                         cmd.Stdout = stdout
465                         cmd.Stderr = stderr
466                         err = cmd.Start()
467                         if err != nil {
468                                 return 1
469                         }
470                         defer func() {
471                                 cmd.Process.Signal(syscall.SIGTERM)
472                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
473                                 cmd.Wait()
474                         }()
475                         err = waitPostgreSQLReady()
476                         if err != nil {
477                                 return 1
478                         }
479                 }
480
481                 if os.Getpid() == 1 {
482                         // We are the init process (presumably in a
483                         // docker container) so although postgresql is
484                         // installed, it's not running, and initdb
485                         // might never have been run.
486                 }
487
488                 var needcoll []string
489                 // If the en_US.UTF-8 locale wasn't installed when
490                 // postgresql initdb ran, it needs to be added
491                 // explicitly before we can use it in our test suite.
492                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
493                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
494                         cmd.Dir = "/"
495                         out, err2 := cmd.CombinedOutput()
496                         if err != nil {
497                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
498                                 return 1
499                         }
500                         if strings.Contains(string(out), "1") {
501                                 logger.Infof("postgresql supports collation %s", collname)
502                         } else {
503                                 needcoll = append(needcoll, collname)
504                         }
505                 }
506                 if len(needcoll) > 0 && os.Getpid() != 1 {
507                         // In order for the CREATE COLLATION statement
508                         // below to work, the locale must have existed
509                         // when PostgreSQL started up. If we're
510                         // running as init, we must have started
511                         // PostgreSQL ourselves after installing the
512                         // locales. Otherwise, it might need a
513                         // restart, so we attempt to restart it with
514                         // systemd.
515                         if err = inst.runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
516                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
517                         } else if err = waitPostgreSQLReady(); err != nil {
518                                 return 1
519                         }
520                 }
521                 for _, collname := range needcoll {
522                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
523                         cmd.Stdout = stdout
524                         cmd.Stderr = stderr
525                         cmd.Dir = "/"
526                         err = cmd.Run()
527                         if err != nil {
528                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
529                                 return 1
530                         }
531                 }
532
533                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
534                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
535                 cmd.Dir = "/"
536                 if err := cmd.Run(); err == nil {
537                         logger.Print("arvados role exists; superuser privileges added, password updated")
538                 } else {
539                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
540                         cmd.Dir = "/"
541                         cmd.Stdout = stdout
542                         cmd.Stderr = stderr
543                         err = cmd.Run()
544                         if err != nil {
545                                 return 1
546                         }
547                 }
548         }
549
550         if !prod {
551                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == nodejsversion+"\n" {
552                         logger.Print("nodejs " + nodejsversion + " already installed")
553                 } else {
554                         err = inst.runBash(`
555 NJS=`+nodejsversion+`
556 rm -rf /var/lib/arvados/node-*-linux-x64
557 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
558 ln -sfv /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
559 `, stdout, stderr)
560                         if err != nil {
561                                 return 1
562                         }
563                 }
564
565                 if haveyarnversion, err := exec.Command("/usr/local/bin/yarn", "--version").CombinedOutput(); err == nil && len(haveyarnversion) > 0 {
566                         logger.Print("yarn " + strings.TrimSpace(string(haveyarnversion)) + " already installed")
567                 } else {
568                         err = inst.runBash(`
569 npm install -g yarn
570 ln -sfv /var/lib/arvados/node-`+nodejsversion+`-linux-x64/bin/{yarn,yarnpkg} /usr/local/bin/
571 `, stdout, stderr)
572                         if err != nil {
573                                 return 1
574                         }
575                 }
576         }
577
578         if prod || pkg {
579                 // Install Go programs to /var/lib/arvados/bin/
580                 for _, srcdir := range []string{
581                         "cmd/arvados-client",
582                         "cmd/arvados-server",
583                 } {
584                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
585                         // -buildvcs=false here avoids a fatal "error
586                         // obtaining VCS status" when git refuses to
587                         // run (for example) as root in a docker
588                         // container using a non-root-owned git tree
589                         // mounted from the host -- as in
590                         // "arvados-package build".
591                         cmd := exec.Command("go", "install", "-buildvcs=false",
592                                 "-ldflags", "-s -w"+
593                                         " -X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+
594                                         " -X git.arvados.org/arvados.git/lib/cmd.commit="+inst.Commit)
595                         cmd.Env = append(cmd.Env, os.Environ()...)
596                         cmd.Env = append(cmd.Env, "GOBIN=/var/lib/arvados/bin")
597                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
598                         cmd.Stdout = stdout
599                         cmd.Stderr = stderr
600                         err = cmd.Run()
601                         if err != nil {
602                                 return 1
603                         }
604                 }
605
606                 // Copy assets from source tree to /var/lib/arvados/share
607                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
608                 cmd.Stdout = stdout
609                 cmd.Stderr = stderr
610                 err = cmd.Run()
611                 if err != nil {
612                         return 1
613                 }
614
615                 // Install python SDK and arv-mount in
616                 // /var/lib/arvados/lib/python.
617                 //
618                 // setup.py writes a file in the source directory in
619                 // order to include the version number in the package
620                 // itself.  We don't want to write to the source tree
621                 // (in "arvados-package" context it's mounted
622                 // readonly) so we run setup.py in a temporary copy of
623                 // the source dir.
624                 if err = inst.runBash(`
625 v=/var/lib/arvados/lib/python
626 tmp=/var/lib/arvados/tmp/python
627 python3 -m venv "$v"
628 . "$v/bin/activate"
629 pip3 install --no-cache-dir 'setuptools>=68' 'pip>=20'
630 export ARVADOS_BUILDING_VERSION="`+inst.PackageVersion+`"
631 for src in "`+inst.SourcePath+`/sdk/python" "`+inst.SourcePath+`/services/fuse"; do
632   rsync -a --delete-after "$src/" "$tmp/"
633   env -C "$tmp" python3 setup.py build
634   pip3 install "$tmp"
635   rm -rf "$tmp"
636 done
637 `, stdout, stderr); err != nil {
638                         return 1
639                 }
640
641                 // Install RailsAPI to /var/lib/arvados/railsapi/
642                 fmt.Fprintln(stderr, "building railsapi...")
643                 cmd = exec.Command("rsync",
644                         "-a", "--no-owner", "--no-group", "--delete-after", "--delete-excluded",
645                         "--exclude", "/coverage",
646                         "--exclude", "/log",
647                         "--exclude", "/node_modules",
648                         "--exclude", "/tmp",
649                         "--exclude", "/public/assets",
650                         "--exclude", "/vendor",
651                         "--exclude", "/config/environments",
652                         "./", "/var/lib/arvados/railsapi/")
653                 cmd.Dir = filepath.Join(inst.SourcePath, "services", "api")
654                 cmd.Stdout = stdout
655                 cmd.Stderr = stderr
656                 err = cmd.Run()
657                 if err != nil {
658                         return 1
659                 }
660                 for _, cmdline := range [][]string{
661                         {"mkdir", "-p", "log", "public/assets", "tmp", "vendor", ".bundle", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger"},
662                         {"touch", "log/production.log"},
663                         {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger", "log", "tmp", "vendor", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
664                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:" + bundlerversion},
665                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "deployment", "true"},
666                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "path", "/var/www/.gem"},
667                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "without", "development test diagnostics performance"},
668                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--jobs", fmt.Sprintf("%d", runtime.NumCPU())},
669
670                         {"chown", "www-data:www-data", ".", "public/assets"},
671                         // {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "system", "true"},
672                         {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "npm:install"},
673                         {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "assets:precompile"},
674                         {"chown", "root:root", "."},
675                         {"chown", "-R", "root:root", "public/assets", "vendor"},
676
677                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
678                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
679                 } {
680                         if cmdline[len(cmdline)-2] == "rake" {
681                                 continue
682                         }
683                         cmd = exec.Command(cmdline[0], cmdline[1:]...)
684                         cmd.Dir = "/var/lib/arvados/railsapi"
685                         cmd.Stdout = stdout
686                         cmd.Stderr = stderr
687                         fmt.Fprintf(stderr, "... %s\n", cmd.Args)
688                         err = cmd.Run()
689                         if err != nil {
690                                 return 1
691                         }
692                 }
693                 cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
694                 cmd.Dir = "/var/lib/arvados/railsapi"
695                 cmd.Stdout = stdout
696                 cmd.Stderr = stderr
697                 err = cmd.Run()
698                 if err != nil && !strings.Contains(err.Error(), "exit status 2") {
699                         // Exit code 2 indicates there were warnings (like
700                         // "other passenger installations have been detected",
701                         // which we can't expect to avoid) but no errors.
702                         // Other non-zero exit codes (1, 9) indicate errors.
703                         return 1
704                 }
705
706                 // Install workbench2 app to
707                 // /var/lib/arvados/workbench2/.
708                 //
709                 // We copy the source tree from the (possibly
710                 // readonly) source tree into a temp dir because `yarn
711                 // build` writes to {source-tree}/build/. When we
712                 // upgrade to react-scripts >= 4.0.2 we may be able to
713                 // build from the source dir and write directly to the
714                 // final destination (using
715                 // YARN_INSTALL_STATE_PATH=/dev/null
716                 // BUILD_PATH=/var/lib/arvados/workbench2) instead of
717                 // using two rsync steps here.
718                 if err = inst.runBash(`
719 src="`+inst.SourcePath+`/services/workbench2"
720 tmp=/var/lib/arvados/tmp/workbench2
721 trap "rm -r ${tmp}" ERR EXIT
722 dst=/var/lib/arvados/workbench2
723 rsync -a --delete-after "$src/" "$tmp/"
724 env -C "$tmp" VERSION="`+inst.PackageVersion+`" BUILD_NUMBER=1 GIT_COMMIT="`+inst.Commit[:9]+`" yarn build
725 rsync -a --delete-after "$tmp/build/" "$dst/"
726 `, stdout, stderr); err != nil {
727                         return 1
728                 }
729
730                 // Install arvados-cli gem (binaries go in
731                 // /var/lib/arvados/bin)
732                 if err = inst.runBash(`
733 /var/lib/arvados/bin/gem install --conservative --no-document arvados-cli
734 `, stdout, stderr); err != nil {
735                         return 1
736                 }
737
738                 err = os.WriteFile("/lib/systemd/system/arvados.service", arvadosServiceFile, 0777)
739                 if err != nil {
740                         return 1
741                 }
742                 if prod {
743                         // (fpm will do this for us in the pkg case)
744                         // This is equivalent to "systemd enable", but
745                         // does not depend on the systemctl program
746                         // being available:
747                         symlink := "/etc/systemd/system/multi-user.target.wants/arvados.service"
748                         err = os.Remove(symlink)
749                         if err != nil && !errors.Is(err, os.ErrNotExist) {
750                                 return 1
751                         }
752                         err = os.Symlink("/lib/systemd/system/arvados.service", symlink)
753                         if err != nil {
754                                 return 1
755                         }
756                 }
757
758                 // Add symlinks in /usr/bin for user-facing programs
759                 for _, srcdst := range [][]string{
760                         // go
761                         {"bin/arvados-client"},
762                         {"bin/arvados-client", "arv"},
763                         {"bin/arvados-server"},
764                         // sdk/cli
765                         {"bin/arv", "arv-ruby"},
766                         {"bin/arv-tag"},
767                         // sdk/python
768                         {"lib/python/bin/arv-copy"},
769                         {"lib/python/bin/arv-federation-migrate"},
770                         {"lib/python/bin/arv-get"},
771                         {"lib/python/bin/arv-keepdocker"},
772                         {"lib/python/bin/arv-ls"},
773                         {"lib/python/bin/arv-migrate-docker19"},
774                         {"lib/python/bin/arv-normalize"},
775                         {"lib/python/bin/arv-put"},
776                         {"lib/python/bin/arv-ws"},
777                         // services/fuse
778                         {"lib/python/bin/arv-mount"},
779                 } {
780                         src := "/var/lib/arvados/" + srcdst[0]
781                         if _, err = os.Stat(src); err != nil {
782                                 return 1
783                         }
784                         dst := srcdst[len(srcdst)-1]
785                         _, dst = filepath.Split(dst)
786                         dst = "/usr/bin/" + dst
787                         err = os.Remove(dst)
788                         if err != nil && !errors.Is(err, os.ErrNotExist) {
789                                 return 1
790                         }
791                         err = os.Symlink(src, dst)
792                         if err != nil {
793                                 return 1
794                         }
795                 }
796         }
797
798         return 0
799 }
800
801 type osversion struct {
802         Debian bool
803         Ubuntu bool
804         Centos bool
805         Major  int
806 }
807
808 func identifyOS() (osversion, error) {
809         var osv osversion
810         f, err := os.Open("/etc/os-release")
811         if err != nil {
812                 return osv, err
813         }
814         defer f.Close()
815
816         kv := map[string]string{}
817         scanner := bufio.NewScanner(f)
818         for scanner.Scan() {
819                 line := strings.TrimSpace(scanner.Text())
820                 if strings.HasPrefix(line, "#") {
821                         continue
822                 }
823                 toks := strings.SplitN(line, "=", 2)
824                 if len(toks) != 2 {
825                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
826                 }
827                 k := toks[0]
828                 v := strings.Trim(toks[1], `"`)
829                 if v == toks[1] {
830                         v = strings.Trim(v, `'`)
831                 }
832                 kv[k] = v
833         }
834         if err = scanner.Err(); err != nil {
835                 return osv, err
836         }
837         switch kv["ID"] {
838         case "ubuntu":
839                 osv.Ubuntu = true
840         case "debian":
841                 osv.Debian = true
842         case "centos":
843                 osv.Centos = true
844         default:
845                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
846         }
847         vstr := kv["VERSION_ID"]
848         if i := strings.Index(vstr, "."); i > 0 {
849                 vstr = vstr[:i]
850         }
851         osv.Major, err = strconv.Atoi(vstr)
852         if err != nil {
853                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
854         }
855         return osv, nil
856 }
857
858 func waitPostgreSQLReady() error {
859         for deadline := time.Now().Add(10 * time.Second); ; {
860                 output, err := exec.Command("pg_isready").CombinedOutput()
861                 if err == nil {
862                         return nil
863                 } else if time.Now().After(deadline) {
864                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
865                 } else {
866                         time.Sleep(time.Second)
867                 }
868         }
869 }
870
871 func (inst *installCommand) runBash(script string, stdout, stderr io.Writer) error {
872         cmd := exec.Command("bash", "-")
873         if inst.EatMyData {
874                 cmd = exec.Command("eatmydata", "bash", "-")
875         }
876         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
877         cmd.Stdout = stdout
878         cmd.Stderr = stderr
879         return cmd.Run()
880 }
881
882 func prodpkgs(osv osversion) []string {
883         pkgs := []string{
884                 "ca-certificates",
885                 "curl",
886                 "fuse",
887                 "git",
888                 "gitolite3",
889                 "graphviz",
890                 "haveged",
891                 "libcurl3-gnutls",
892                 "libxslt1.1",
893                 "nginx",
894                 "python3",
895                 "sudo",
896         }
897         if osv.Debian || osv.Ubuntu {
898                 if osv.Debian && osv.Major == 8 {
899                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
900                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
901                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
902                 }
903                 return append(pkgs,
904                         "mime-support", // keep-web
905                 )
906         } else if osv.Centos {
907                 return append(pkgs,
908                         "fuse-libs", // services/fuse
909                         "mailcap",   // keep-web
910                 )
911         } else {
912                 panic("os version not supported")
913         }
914 }
915
916 func ProductionDependencies() ([]string, error) {
917         osv, err := identifyOS()
918         if err != nil {
919                 return nil, err
920         }
921         return prodpkgs(osv), nil
922 }