20846: Specify nodejs version without 'v' prefix.
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         _ "embed"
12         "errors"
13         "flag"
14         "fmt"
15         "io"
16         "os"
17         "os/exec"
18         "os/user"
19         "path/filepath"
20         "regexp"
21         "runtime"
22         "strconv"
23         "strings"
24         "syscall"
25         "time"
26
27         "git.arvados.org/arvados.git/lib/cmd"
28         "git.arvados.org/arvados.git/sdk/go/ctxlog"
29         "github.com/lib/pq"
30 )
31
32 var Command cmd.Handler = &installCommand{}
33
34 const goversion = "1.20.6"
35
36 const (
37         defaultRubyVersion        = "3.2.2"
38         defaultBundlerVersion     = "2.2.19"
39         defaultSingularityVersion = "3.10.4"
40         pjsversion                = "1.9.8"
41         geckoversion              = "0.24.0"
42         gradleversion             = "5.3.1"
43         defaultNodejsVersion      = "12.22.12"
44         devtestDatabasePassword   = "insecure_arvados_test"
45 )
46
47 //go:embed arvados.service
48 var arvadosServiceFile []byte
49
50 type installCommand struct {
51         ClusterType        string
52         SourcePath         string
53         Commit             string
54         PackageVersion     string
55         RubyVersion        string
56         BundlerVersion     string
57         SingularityVersion string
58         NodejsVersion      string
59         EatMyData          bool
60 }
61
62 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
63         logger := ctxlog.New(stderr, "text", "info")
64         ctx := ctxlog.Context(context.Background(), logger)
65         ctx, cancel := context.WithCancel(ctx)
66         defer cancel()
67
68         var err error
69         defer func() {
70                 if err != nil {
71                         logger.WithError(err).Info("exiting")
72                 }
73         }()
74
75         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
76         flags.SetOutput(stderr)
77         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
78         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
79         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
80         flags.StringVar(&inst.Commit, "commit", "", "source commit `hash` to embed (blank means use 'git log' or all-zero placeholder)")
81         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
82         flags.StringVar(&inst.RubyVersion, "ruby-version", defaultRubyVersion, "Ruby `version` to install (do not override in production mode)")
83         flags.StringVar(&inst.BundlerVersion, "bundler-version", defaultBundlerVersion, "Bundler `version` to install (do not override in production mode)")
84         flags.StringVar(&inst.SingularityVersion, "singularity-version", defaultSingularityVersion, "Singularity `version` to install (do not override in production mode)")
85         flags.StringVar(&inst.NodejsVersion, "nodejs-version", defaultNodejsVersion, "Nodejs `version` to install (not applicable in production mode)")
86         flags.BoolVar(&inst.EatMyData, "eatmydata", false, "use eatmydata to speed up install")
87
88         if ok, code := cmd.ParseFlags(flags, prog, args, "", stderr); !ok {
89                 return code
90         } else if *versionFlag {
91                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
92         }
93
94         if inst.Commit == "" {
95                 if commit, err := exec.Command("env", "-C", inst.SourcePath, "git", "log", "-n1", "--format=%H").CombinedOutput(); err == nil {
96                         inst.Commit = strings.TrimSpace(string(commit))
97                 } else {
98                         inst.Commit = "0000000000000000000000000000000000000000"
99                 }
100         }
101
102         var dev, test, prod, pkg bool
103         switch inst.ClusterType {
104         case "development":
105                 dev = true
106         case "test":
107                 test = true
108         case "production":
109                 prod = true
110         case "package":
111                 pkg = true
112         default:
113                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
114                 return 2
115         }
116
117         if prod {
118                 err = errors.New("production install is not yet implemented")
119                 return 1
120         }
121
122         if ok, _ := regexp.MatchString(`^\d\.\d+\.\d+$`, inst.RubyVersion); !ok {
123                 fmt.Fprintf(stderr, "invalid argument %q for -ruby-version\n", inst.RubyVersion)
124                 return 2
125         }
126         if ok, _ := regexp.MatchString(`^\d`, inst.BundlerVersion); !ok {
127                 fmt.Fprintf(stderr, "invalid argument %q for -bundler-version\n", inst.BundlerVersion)
128                 return 2
129         }
130         if ok, _ := regexp.MatchString(`^\d`, inst.SingularityVersion); !ok {
131                 fmt.Fprintf(stderr, "invalid argument %q for -singularity-version\n", inst.SingularityVersion)
132                 return 2
133         }
134         if ok, _ := regexp.MatchString(`^\d`, inst.NodejsVersion); !ok {
135                 fmt.Fprintf(stderr, "invalid argument %q for -nodejs-version\n", inst.NodejsVersion)
136                 return 2
137         }
138
139         osv, err := identifyOS()
140         if err != nil {
141                 return 1
142         }
143
144         listdir, err := os.Open("/var/lib/apt/lists")
145         if err != nil {
146                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
147         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
148                 // Special case for a base docker image where the
149                 // package cache has been deleted and all "apt-get
150                 // install" commands will fail unless we fetch repos.
151                 cmd := exec.CommandContext(ctx, "apt-get", "update")
152                 cmd.Stdout = stdout
153                 cmd.Stderr = stderr
154                 err = cmd.Run()
155                 if err != nil {
156                         return 1
157                 }
158         }
159
160         if inst.EatMyData {
161                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends", "eatmydata")
162                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
163                 cmd.Stdout = stdout
164                 cmd.Stderr = stderr
165                 err = cmd.Run()
166                 if err != nil {
167                         return 1
168                 }
169         }
170
171         pkgs := prodpkgs(osv)
172
173         if pkg {
174                 pkgs = append(pkgs,
175                         "dpkg-dev",
176                         "eatmydata", // install it for later steps, even if we're not using it now
177                 )
178         }
179
180         if dev || test || pkg {
181                 pkgs = append(pkgs,
182                         "automake",
183                         "bison",
184                         "bsdmainutils",
185                         "build-essential",
186                         "cadaver",
187                         "curl",
188                         "cython3",
189                         "default-jdk-headless",
190                         "default-jre-headless",
191                         "gettext",
192                         "libattr1-dev",
193                         "libffi-dev",
194                         "libfuse-dev",
195                         "libgbm1", // cypress / workbench2 tests
196                         "libgnutls28-dev",
197                         "libpam-dev",
198                         "libpcre3-dev",
199                         "libpq-dev",
200                         "libreadline-dev",
201                         "libssl-dev",
202                         "libxml2-dev",
203                         "libxslt1-dev",
204                         "libyaml-dev",
205                         "linkchecker",
206                         "lsof",
207                         "make",
208                         "net-tools",
209                         "pandoc",
210                         "pkg-config",
211                         "postgresql",
212                         "postgresql-contrib",
213                         "python3-dev",
214                         "python3-venv",
215                         "python3-virtualenv",
216                         "r-base",
217                         "r-cran-testthat",
218                         "r-cran-devtools",
219                         "r-cran-knitr",
220                         "r-cran-markdown",
221                         "r-cran-roxygen2",
222                         "r-cran-xml",
223                         "rsync",
224                         "sudo",
225                         "uuid-dev",
226                         "wget",
227                         "xvfb",
228                         "zlib1g-dev", // services/api
229                 )
230                 if test {
231                         if osv.Debian && osv.Major <= 10 {
232                                 pkgs = append(pkgs, "iceweasel")
233                         } else if osv.Debian && osv.Major >= 11 {
234                                 pkgs = append(pkgs, "firefox-esr")
235                         } else {
236                                 pkgs = append(pkgs, "firefox")
237                         }
238                 }
239                 if dev || test {
240                         pkgs = append(pkgs,
241                                 "libglib2.0-dev", // singularity (conmon)
242                                 "libseccomp-dev", // singularity (seccomp)
243                                 "squashfs-tools", // singularity
244                                 "gnupg")          // docker install recipe
245                 }
246                 switch {
247                 case osv.Debian && osv.Major >= 10,
248                         osv.Ubuntu && osv.Major >= 22:
249                         pkgs = append(pkgs, "g++", "libcurl4", "libcurl4-openssl-dev")
250                 case osv.Debian || osv.Ubuntu:
251                         pkgs = append(pkgs, "g++", "libcurl3", "libcurl3-openssl-dev")
252                 case osv.Centos:
253                         pkgs = append(pkgs, "gcc", "gcc-c++", "libcurl-devel", "postgresql-devel")
254                 }
255                 cmd := exec.CommandContext(ctx, "apt-get")
256                 if inst.EatMyData {
257                         cmd = exec.CommandContext(ctx, "eatmydata", "apt-get")
258                 }
259                 cmd.Args = append(cmd.Args, "install", "--yes", "--no-install-recommends")
260                 cmd.Args = append(cmd.Args, pkgs...)
261                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
262                 cmd.Stdout = stdout
263                 cmd.Stderr = stderr
264                 err = cmd.Run()
265                 if err != nil {
266                         return 1
267                 }
268         }
269
270         if dev || test {
271                 if havedockerversion, err2 := exec.Command("docker", "--version").CombinedOutput(); err2 == nil {
272                         logger.Printf("%s installed, assuming that version is ok", bytes.TrimSuffix(havedockerversion, []byte("\n")))
273                 } else if osv.Debian {
274                         var codename string
275                         switch osv.Major {
276                         case 10:
277                                 codename = "buster"
278                         case 11:
279                                 codename = "bullseye"
280                         case 12:
281                                 codename = "bookworm"
282                         default:
283                                 err = fmt.Errorf("don't know how to install docker-ce for debian %d", osv.Major)
284                                 return 1
285                         }
286                         err = inst.runBash(`
287 rm -f /usr/share/keyrings/docker-archive-keyring.gpg
288 curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
289 echo 'deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian/ `+codename+` stable' | \
290     tee /etc/apt/sources.list.d/docker.list
291 apt-get update
292 DEBIAN_FRONTEND=noninteractive apt-get --yes --no-install-recommends install docker-ce
293 `, stdout, stderr)
294                         if err != nil {
295                                 return 1
296                         }
297                 } else {
298                         err = fmt.Errorf("don't know how to install docker for osversion %v", osv)
299                         return 1
300                 }
301
302                 err = inst.runBash(`
303 key=fs.inotify.max_user_watches
304 min=524288
305 if [[ "$(sysctl --values "${key}")" -lt "${min}" ]]; then
306     sysctl "${key}=${min}"
307     # writing sysctl worked, so we should make it permanent
308     echo "${key}=${min}" | tee -a /etc/sysctl.conf
309     sysctl -p
310 fi
311 `, stdout, stderr)
312                 if err != nil {
313                         err = fmt.Errorf("couldn't set fs.inotify.max_user_watches value. (Is this a docker container? Fix this on the docker host by adding fs.inotify.max_user_watches=524288 to /etc/sysctl.conf and running `sysctl -p`)")
314                         return 1
315                 }
316         }
317
318         os.Mkdir("/var/lib/arvados", 0755)
319         os.Mkdir("/var/lib/arvados/tmp", 0700)
320         if prod || pkg {
321                 u, er := user.Lookup("www-data")
322                 if er != nil {
323                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
324                         return 1
325                 }
326                 uid, _ := strconv.Atoi(u.Uid)
327                 gid, _ := strconv.Atoi(u.Gid)
328                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
329                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
330                 if err != nil {
331                         return 1
332                 }
333         }
334         rubyminorversion := inst.RubyVersion[:strings.LastIndex(inst.RubyVersion, ".")]
335         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+inst.RubyVersion)) {
336                 logger.Print("ruby " + inst.RubyVersion + " already installed")
337         } else {
338                 err = inst.runBash(`
339 rubyversion="`+inst.RubyVersion+`"
340 rubyminorversion="`+rubyminorversion+`"
341 tmp="$(mktemp -d)"
342 trap 'rm -r "${tmp}"' ERR EXIT
343 wget --progress=dot:giga -O- "https://cache.ruby-lang.org/pub/ruby/$rubyminorversion/ruby-$rubyversion.tar.gz" | tar -C "${tmp}" -xzf -
344 cd "${tmp}/ruby-$rubyversion"
345 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
346 make -j8
347 rm -f /var/lib/arvados/bin/erb
348 make install
349 if [[ "$rubyversion" > "3" ]]; then
350   /var/lib/arvados/bin/gem update --no-document --system 3.4.21
351 fi
352 /var/lib/arvados/bin/gem install bundler --no-document
353 `, stdout, stderr)
354                 if err != nil {
355                         return 1
356                 }
357         }
358
359         if !prod {
360                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
361                         logger.Print("go " + goversion + " already installed")
362                 } else {
363                         err = inst.runBash(`
364 cd /tmp
365 rm -rf /var/lib/arvados/go/
366 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
367 ln -sfv /var/lib/arvados/go/bin/* /usr/local/bin/
368 `, stdout, stderr)
369                         if err != nil {
370                                 return 1
371                         }
372                 }
373         }
374
375         if !prod && !pkg {
376                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
377                         logger.Print("phantomjs " + pjsversion + " already installed")
378                 } else {
379                         err = inst.runBash(`
380 PJS=phantomjs-`+pjsversion+`-linux-x86_64
381 wget --progress=dot:giga -O- https://cache.arvados.org/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
382 ln -sfv /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
383 `, stdout, stderr)
384                         if err != nil {
385                                 return 1
386                         }
387                 }
388
389                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
390                         logger.Print("geckodriver " + geckoversion + " already installed")
391                 } else {
392                         err = inst.runBash(`
393 GD=v`+geckoversion+`
394 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
395 ln -sfv /var/lib/arvados/bin/geckodriver /usr/local/bin/
396 `, stdout, stderr)
397                         if err != nil {
398                                 return 1
399                         }
400                 }
401
402                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
403                         logger.Print("gradle " + gradleversion + " already installed")
404                 } else {
405                         err = inst.runBash(`
406 G=`+gradleversion+`
407 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
408 trap "rm ${zip}" ERR
409 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
410 unzip -o -d /var/lib/arvados ${zip}
411 ln -sfv /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
412 rm ${zip}
413 `, stdout, stderr)
414                         if err != nil {
415                                 return 1
416                         }
417                 }
418
419                 if havesingularityversion, err := exec.Command("/var/lib/arvados/bin/singularity", "--version").CombinedOutput(); err == nil && strings.Contains(string(havesingularityversion), inst.SingularityVersion) {
420                         logger.Print("singularity " + inst.SingularityVersion + " already installed")
421                 } else if dev || test {
422                         err = inst.runBash(`
423 S=`+inst.SingularityVersion+`
424 tmp=/var/lib/arvados/tmp/singularity
425 trap "rm -r ${tmp}" ERR EXIT
426 cd /var/lib/arvados/tmp
427 git clone --recurse-submodules https://github.com/sylabs/singularity
428 cd singularity
429 git checkout v${S}
430 ./mconfig --prefix=/var/lib/arvados
431 make -C ./builddir
432 make -C ./builddir install
433 `, stdout, stderr)
434                         if err != nil {
435                                 return 1
436                         }
437                 }
438
439                 err = inst.runBash(`
440 install /usr/bin/nsenter /var/lib/arvados/bin/nsenter
441 setcap "cap_sys_admin+pei cap_sys_chroot+pei" /var/lib/arvados/bin/nsenter
442 `, stdout, stderr)
443                 if err != nil {
444                         return 1
445                 }
446
447                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
448                 // it's installed, locale -a reports it as
449                 // "en_US.utf8".
450                 wantlocale := "en_US.UTF-8"
451                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
452                         logger.Print("locale " + wantlocale + " already installed")
453                 } else {
454                         err = inst.runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
455                         if err != nil {
456                                 return 1
457                         }
458                 }
459
460                 var pgc struct {
461                         Version       string
462                         Cluster       string
463                         Port          int
464                         Status        string
465                         Owner         string
466                         DataDirectory string
467                         LogFile       string
468                 }
469                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
470                         err = fmt.Errorf("pg_lsclusters: %s", err2)
471                         return 1
472                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
473                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
474                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
475                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
476                         return 1
477                 } else if pgc.Status == "online" {
478                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
479                 } else {
480                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
481                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
482                         cmd.Stdout = stdout
483                         cmd.Stderr = stderr
484                         err = cmd.Start()
485                         if err != nil {
486                                 return 1
487                         }
488                         defer func() {
489                                 cmd.Process.Signal(syscall.SIGTERM)
490                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
491                                 cmd.Wait()
492                         }()
493                         err = waitPostgreSQLReady()
494                         if err != nil {
495                                 return 1
496                         }
497                 }
498
499                 if os.Getpid() == 1 {
500                         // We are the init process (presumably in a
501                         // docker container) so although postgresql is
502                         // installed, it's not running, and initdb
503                         // might never have been run.
504                 }
505
506                 var needcoll []string
507                 // If the en_US.UTF-8 locale wasn't installed when
508                 // postgresql initdb ran, it needs to be added
509                 // explicitly before we can use it in our test suite.
510                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
511                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
512                         cmd.Dir = "/"
513                         out, err2 := cmd.CombinedOutput()
514                         if err != nil {
515                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
516                                 return 1
517                         }
518                         if strings.Contains(string(out), "1") {
519                                 logger.Infof("postgresql supports collation %s", collname)
520                         } else {
521                                 needcoll = append(needcoll, collname)
522                         }
523                 }
524                 if len(needcoll) > 0 && os.Getpid() != 1 {
525                         // In order for the CREATE COLLATION statement
526                         // below to work, the locale must have existed
527                         // when PostgreSQL started up. If we're
528                         // running as init, we must have started
529                         // PostgreSQL ourselves after installing the
530                         // locales. Otherwise, it might need a
531                         // restart, so we attempt to restart it with
532                         // systemd.
533                         if err = inst.runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
534                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
535                         } else if err = waitPostgreSQLReady(); err != nil {
536                                 return 1
537                         }
538                 }
539                 for _, collname := range needcoll {
540                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
541                         cmd.Stdout = stdout
542                         cmd.Stderr = stderr
543                         cmd.Dir = "/"
544                         err = cmd.Run()
545                         if err != nil {
546                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
547                                 return 1
548                         }
549                 }
550
551                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
552                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
553                 cmd.Dir = "/"
554                 if err := cmd.Run(); err == nil {
555                         logger.Print("arvados role exists; superuser privileges added, password updated")
556                 } else {
557                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
558                         cmd.Dir = "/"
559                         cmd.Stdout = stdout
560                         cmd.Stderr = stderr
561                         err = cmd.Run()
562                         if err != nil {
563                                 return 1
564                         }
565                 }
566         }
567
568         if !prod {
569                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == "v"+inst.NodejsVersion+"\n" {
570                         logger.Print("nodejs " + inst.NodejsVersion + " already installed")
571                 } else {
572                         err = inst.runBash(`
573 NJS=v`+inst.NodejsVersion+`
574 rm -rf /var/lib/arvados/node-*-linux-x64
575 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
576 ln -sfv /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
577 `, stdout, stderr)
578                         if err != nil {
579                                 return 1
580                         }
581                 }
582
583                 if haveyarnversion, err := exec.Command("/usr/local/bin/yarn", "--version").CombinedOutput(); err == nil && len(haveyarnversion) > 0 {
584                         logger.Print("yarn " + strings.TrimSpace(string(haveyarnversion)) + " already installed")
585                 } else {
586                         err = inst.runBash(`
587 npm install -g yarn
588 ln -sfv /var/lib/arvados/node-v`+inst.NodejsVersion+`-linux-x64/bin/{yarn,yarnpkg} /usr/local/bin/
589 `, stdout, stderr)
590                         if err != nil {
591                                 return 1
592                         }
593                 }
594         }
595
596         if prod || pkg {
597                 // Install Go programs to /var/lib/arvados/bin/
598                 for _, srcdir := range []string{
599                         "cmd/arvados-client",
600                         "cmd/arvados-server",
601                 } {
602                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
603                         // -buildvcs=false here avoids a fatal "error
604                         // obtaining VCS status" when git refuses to
605                         // run (for example) as root in a docker
606                         // container using a non-root-owned git tree
607                         // mounted from the host -- as in
608                         // "arvados-package build".
609                         cmd := exec.Command("go", "install", "-buildvcs=false",
610                                 "-ldflags", "-s -w"+
611                                         " -X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+
612                                         " -X git.arvados.org/arvados.git/lib/cmd.commit="+inst.Commit)
613                         cmd.Env = append(cmd.Env, os.Environ()...)
614                         cmd.Env = append(cmd.Env, "GOBIN=/var/lib/arvados/bin")
615                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
616                         cmd.Stdout = stdout
617                         cmd.Stderr = stderr
618                         err = cmd.Run()
619                         if err != nil {
620                                 return 1
621                         }
622                 }
623
624                 // Copy assets from source tree to /var/lib/arvados/share
625                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
626                 cmd.Stdout = stdout
627                 cmd.Stderr = stderr
628                 err = cmd.Run()
629                 if err != nil {
630                         return 1
631                 }
632
633                 // Install python SDK and arv-mount in
634                 // /var/lib/arvados/lib/python.
635                 //
636                 // setup.py writes a file in the source directory in
637                 // order to include the version number in the package
638                 // itself.  We don't want to write to the source tree
639                 // (in "arvados-package" context it's mounted
640                 // readonly) so we run setup.py in a temporary copy of
641                 // the source dir.
642                 if err = inst.runBash(`
643 v=/var/lib/arvados/lib/python
644 tmp=/var/lib/arvados/tmp/python
645 python3 -m venv "$v"
646 . "$v/bin/activate"
647 pip3 install --no-cache-dir 'setuptools>=68' 'pip>=20'
648 export ARVADOS_BUILDING_VERSION="`+inst.PackageVersion+`"
649 for src in "`+inst.SourcePath+`/sdk/python" "`+inst.SourcePath+`/services/fuse"; do
650   rsync -a --delete-after "$src/" "$tmp/"
651   env -C "$tmp" python3 setup.py build
652   pip3 install "$tmp"
653   rm -rf "$tmp"
654 done
655 `, stdout, stderr); err != nil {
656                         return 1
657                 }
658
659                 // Install RailsAPI to /var/lib/arvados/railsapi/
660                 fmt.Fprintln(stderr, "building railsapi...")
661                 cmd = exec.Command("rsync",
662                         "-a", "--no-owner", "--no-group", "--delete-after", "--delete-excluded",
663                         "--exclude", "/coverage",
664                         "--exclude", "/log",
665                         "--exclude", "/node_modules",
666                         "--exclude", "/tmp",
667                         "--exclude", "/public/assets",
668                         "--exclude", "/vendor",
669                         "--exclude", "/config/environments",
670                         "./", "/var/lib/arvados/railsapi/")
671                 cmd.Dir = filepath.Join(inst.SourcePath, "services", "api")
672                 cmd.Stdout = stdout
673                 cmd.Stderr = stderr
674                 err = cmd.Run()
675                 if err != nil {
676                         return 1
677                 }
678                 for _, cmdline := range [][]string{
679                         {"mkdir", "-p", "log", "public/assets", "tmp", "vendor", ".bundle", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger"},
680                         {"touch", "log/production.log"},
681                         {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger", "log", "tmp", "vendor", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
682                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:" + inst.BundlerVersion},
683                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "deployment", "true"},
684                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "path", "/var/www/.gem"},
685                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "without", "development test diagnostics performance"},
686                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--jobs", fmt.Sprintf("%d", runtime.NumCPU())},
687
688                         {"chown", "www-data:www-data", ".", "public/assets"},
689                         // {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "system", "true"},
690                         {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "npm:install"},
691                         {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "assets:precompile"},
692                         {"chown", "root:root", "."},
693                         {"chown", "-R", "root:root", "public/assets", "vendor"},
694
695                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
696                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
697                 } {
698                         if cmdline[len(cmdline)-2] == "rake" {
699                                 continue
700                         }
701                         cmd = exec.Command(cmdline[0], cmdline[1:]...)
702                         cmd.Dir = "/var/lib/arvados/railsapi"
703                         cmd.Stdout = stdout
704                         cmd.Stderr = stderr
705                         fmt.Fprintf(stderr, "... %s\n", cmd.Args)
706                         err = cmd.Run()
707                         if err != nil {
708                                 return 1
709                         }
710                 }
711                 cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
712                 cmd.Dir = "/var/lib/arvados/railsapi"
713                 cmd.Stdout = stdout
714                 cmd.Stderr = stderr
715                 err = cmd.Run()
716                 if err != nil && !strings.Contains(err.Error(), "exit status 2") {
717                         // Exit code 2 indicates there were warnings (like
718                         // "other passenger installations have been detected",
719                         // which we can't expect to avoid) but no errors.
720                         // Other non-zero exit codes (1, 9) indicate errors.
721                         return 1
722                 }
723
724                 // Install workbench2 app to
725                 // /var/lib/arvados/workbench2/.
726                 //
727                 // We copy the source tree from the (possibly
728                 // readonly) source tree into a temp dir because `yarn
729                 // build` writes to {source-tree}/build/. When we
730                 // upgrade to react-scripts >= 4.0.2 we may be able to
731                 // build from the source dir and write directly to the
732                 // final destination (using
733                 // YARN_INSTALL_STATE_PATH=/dev/null
734                 // BUILD_PATH=/var/lib/arvados/workbench2) instead of
735                 // using two rsync steps here.
736                 if err = inst.runBash(`
737 src="`+inst.SourcePath+`/services/workbench2"
738 tmp=/var/lib/arvados/tmp/workbench2
739 trap "rm -r ${tmp}" ERR EXIT
740 dst=/var/lib/arvados/workbench2
741 rsync -a --delete-after "$src/" "$tmp/"
742 env -C "$tmp" VERSION="`+inst.PackageVersion+`" BUILD_NUMBER=1 GIT_COMMIT="`+inst.Commit[:9]+`" yarn build
743 rsync -a --delete-after "$tmp/build/" "$dst/"
744 `, stdout, stderr); err != nil {
745                         return 1
746                 }
747
748                 // Install arvados-cli gem (binaries go in
749                 // /var/lib/arvados/bin)
750                 if err = inst.runBash(`
751 /var/lib/arvados/bin/gem install --conservative --no-document arvados-cli
752 `, stdout, stderr); err != nil {
753                         return 1
754                 }
755
756                 err = os.WriteFile("/lib/systemd/system/arvados.service", arvadosServiceFile, 0777)
757                 if err != nil {
758                         return 1
759                 }
760                 if prod {
761                         // (fpm will do this for us in the pkg case)
762                         // This is equivalent to "systemd enable", but
763                         // does not depend on the systemctl program
764                         // being available:
765                         symlink := "/etc/systemd/system/multi-user.target.wants/arvados.service"
766                         err = os.Remove(symlink)
767                         if err != nil && !errors.Is(err, os.ErrNotExist) {
768                                 return 1
769                         }
770                         err = os.Symlink("/lib/systemd/system/arvados.service", symlink)
771                         if err != nil {
772                                 return 1
773                         }
774                 }
775
776                 // Add symlinks in /usr/bin for user-facing programs
777                 for _, srcdst := range [][]string{
778                         // go
779                         {"bin/arvados-client"},
780                         {"bin/arvados-client", "arv"},
781                         {"bin/arvados-server"},
782                         // sdk/cli
783                         {"bin/arv", "arv-ruby"},
784                         {"bin/arv-tag"},
785                         // sdk/python
786                         {"lib/python/bin/arv-copy"},
787                         {"lib/python/bin/arv-federation-migrate"},
788                         {"lib/python/bin/arv-get"},
789                         {"lib/python/bin/arv-keepdocker"},
790                         {"lib/python/bin/arv-ls"},
791                         {"lib/python/bin/arv-migrate-docker19"},
792                         {"lib/python/bin/arv-normalize"},
793                         {"lib/python/bin/arv-put"},
794                         {"lib/python/bin/arv-ws"},
795                         // services/fuse
796                         {"lib/python/bin/arv-mount"},
797                 } {
798                         src := "/var/lib/arvados/" + srcdst[0]
799                         if _, err = os.Stat(src); err != nil {
800                                 return 1
801                         }
802                         dst := srcdst[len(srcdst)-1]
803                         _, dst = filepath.Split(dst)
804                         dst = "/usr/bin/" + dst
805                         err = os.Remove(dst)
806                         if err != nil && !errors.Is(err, os.ErrNotExist) {
807                                 return 1
808                         }
809                         err = os.Symlink(src, dst)
810                         if err != nil {
811                                 return 1
812                         }
813                 }
814         }
815
816         return 0
817 }
818
819 type osversion struct {
820         Debian bool
821         Ubuntu bool
822         Centos bool
823         Major  int
824 }
825
826 func identifyOS() (osversion, error) {
827         var osv osversion
828         f, err := os.Open("/etc/os-release")
829         if err != nil {
830                 return osv, err
831         }
832         defer f.Close()
833
834         kv := map[string]string{}
835         scanner := bufio.NewScanner(f)
836         for scanner.Scan() {
837                 line := strings.TrimSpace(scanner.Text())
838                 if strings.HasPrefix(line, "#") {
839                         continue
840                 }
841                 toks := strings.SplitN(line, "=", 2)
842                 if len(toks) != 2 {
843                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
844                 }
845                 k := toks[0]
846                 v := strings.Trim(toks[1], `"`)
847                 if v == toks[1] {
848                         v = strings.Trim(v, `'`)
849                 }
850                 kv[k] = v
851         }
852         if err = scanner.Err(); err != nil {
853                 return osv, err
854         }
855         switch kv["ID"] {
856         case "ubuntu":
857                 osv.Ubuntu = true
858         case "debian":
859                 osv.Debian = true
860         case "centos":
861                 osv.Centos = true
862         default:
863                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
864         }
865         vstr := kv["VERSION_ID"]
866         if i := strings.Index(vstr, "."); i > 0 {
867                 vstr = vstr[:i]
868         }
869         osv.Major, err = strconv.Atoi(vstr)
870         if err != nil {
871                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
872         }
873         return osv, nil
874 }
875
876 func waitPostgreSQLReady() error {
877         for deadline := time.Now().Add(10 * time.Second); ; {
878                 output, err := exec.Command("pg_isready").CombinedOutput()
879                 if err == nil {
880                         return nil
881                 } else if time.Now().After(deadline) {
882                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
883                 } else {
884                         time.Sleep(time.Second)
885                 }
886         }
887 }
888
889 func (inst *installCommand) runBash(script string, stdout, stderr io.Writer) error {
890         cmd := exec.Command("bash", "-")
891         if inst.EatMyData {
892                 cmd = exec.Command("eatmydata", "bash", "-")
893         }
894         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
895         cmd.Stdout = stdout
896         cmd.Stderr = stderr
897         return cmd.Run()
898 }
899
900 func prodpkgs(osv osversion) []string {
901         pkgs := []string{
902                 "ca-certificates",
903                 "curl",
904                 "fuse",
905                 "git",
906                 "gitolite3",
907                 "graphviz",
908                 "haveged",
909                 "libcurl3-gnutls",
910                 "libxslt1.1",
911                 "nginx",
912                 "python3",
913                 "sudo",
914         }
915         if osv.Debian || osv.Ubuntu {
916                 if osv.Debian && osv.Major == 8 {
917                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
918                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
919                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
920                 }
921                 return append(pkgs,
922                         "mime-support", // keep-web
923                 )
924         } else if osv.Centos {
925                 return append(pkgs,
926                         "fuse-libs", // services/fuse
927                         "mailcap",   // keep-web
928                 )
929         } else {
930                 panic("os version not supported")
931         }
932 }
933
934 func ProductionDependencies() ([]string, error) {
935         osv, err := identifyOS()
936         if err != nil {
937                 return nil, err
938         }
939         return prodpkgs(osv), nil
940 }