20846: Add -singularity-version option to arvados-server install.
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         _ "embed"
12         "errors"
13         "flag"
14         "fmt"
15         "io"
16         "os"
17         "os/exec"
18         "os/user"
19         "path/filepath"
20         "regexp"
21         "runtime"
22         "strconv"
23         "strings"
24         "syscall"
25         "time"
26
27         "git.arvados.org/arvados.git/lib/cmd"
28         "git.arvados.org/arvados.git/sdk/go/ctxlog"
29         "github.com/lib/pq"
30 )
31
32 var Command cmd.Handler = &installCommand{}
33
34 const goversion = "1.20.6"
35
36 const (
37         defaultRubyVersion        = "3.2.2"
38         defaultBundlerVersion     = "2.2.19"
39         defaultSingularityVersion = "3.10.4"
40         pjsversion                = "1.9.8"
41         geckoversion              = "0.24.0"
42         gradleversion             = "5.3.1"
43         nodejsversion             = "v12.22.12"
44         devtestDatabasePassword   = "insecure_arvados_test"
45 )
46
47 //go:embed arvados.service
48 var arvadosServiceFile []byte
49
50 type installCommand struct {
51         ClusterType        string
52         SourcePath         string
53         Commit             string
54         PackageVersion     string
55         RubyVersion        string
56         BundlerVersion     string
57         SingularityVersion string
58         EatMyData          bool
59 }
60
61 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
62         logger := ctxlog.New(stderr, "text", "info")
63         ctx := ctxlog.Context(context.Background(), logger)
64         ctx, cancel := context.WithCancel(ctx)
65         defer cancel()
66
67         var err error
68         defer func() {
69                 if err != nil {
70                         logger.WithError(err).Info("exiting")
71                 }
72         }()
73
74         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
75         flags.SetOutput(stderr)
76         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
77         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
78         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
79         flags.StringVar(&inst.Commit, "commit", "", "source commit `hash` to embed (blank means use 'git log' or all-zero placeholder)")
80         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
81         flags.StringVar(&inst.RubyVersion, "ruby-version", defaultRubyVersion, "Ruby `version` to install (do not override in production mode)")
82         flags.StringVar(&inst.BundlerVersion, "bundler-version", defaultBundlerVersion, "Bundler `version` to install (do not override in production mode)")
83         flags.StringVar(&inst.SingularityVersion, "singularity-version", defaultSingularityVersion, "Singularity `version` to install (do not override in production mode)")
84         flags.BoolVar(&inst.EatMyData, "eatmydata", false, "use eatmydata to speed up install")
85
86         if ok, code := cmd.ParseFlags(flags, prog, args, "", stderr); !ok {
87                 return code
88         } else if *versionFlag {
89                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
90         }
91
92         if inst.Commit == "" {
93                 if commit, err := exec.Command("env", "-C", inst.SourcePath, "git", "log", "-n1", "--format=%H").CombinedOutput(); err == nil {
94                         inst.Commit = strings.TrimSpace(string(commit))
95                 } else {
96                         inst.Commit = "0000000000000000000000000000000000000000"
97                 }
98         }
99
100         var dev, test, prod, pkg bool
101         switch inst.ClusterType {
102         case "development":
103                 dev = true
104         case "test":
105                 test = true
106         case "production":
107                 prod = true
108         case "package":
109                 pkg = true
110         default:
111                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
112                 return 2
113         }
114
115         if prod {
116                 err = errors.New("production install is not yet implemented")
117                 return 1
118         }
119
120         if ok, _ := regexp.MatchString(`^\d\.\d+\.\d+$`, inst.RubyVersion); !ok {
121                 fmt.Fprintf(stderr, "invalid argument %q for -ruby-version\n", inst.RubyVersion)
122                 return 64
123         }
124         if ok, _ := regexp.MatchString(`^\d`, inst.BundlerVersion); !ok {
125                 fmt.Fprintf(stderr, "invalid argument %q for -bundler-version\n", inst.BundlerVersion)
126                 return 64
127         }
128         if ok, _ := regexp.MatchString(`^\d`, inst.SingularityVersion); !ok {
129                 fmt.Fprintf(stderr, "invalid argument %q for -singularity-version\n", inst.SingularityVersion)
130                 return 64
131         }
132
133         osv, err := identifyOS()
134         if err != nil {
135                 return 1
136         }
137
138         listdir, err := os.Open("/var/lib/apt/lists")
139         if err != nil {
140                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
141         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
142                 // Special case for a base docker image where the
143                 // package cache has been deleted and all "apt-get
144                 // install" commands will fail unless we fetch repos.
145                 cmd := exec.CommandContext(ctx, "apt-get", "update")
146                 cmd.Stdout = stdout
147                 cmd.Stderr = stderr
148                 err = cmd.Run()
149                 if err != nil {
150                         return 1
151                 }
152         }
153
154         if inst.EatMyData {
155                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends", "eatmydata")
156                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
157                 cmd.Stdout = stdout
158                 cmd.Stderr = stderr
159                 err = cmd.Run()
160                 if err != nil {
161                         return 1
162                 }
163         }
164
165         pkgs := prodpkgs(osv)
166
167         if pkg {
168                 pkgs = append(pkgs,
169                         "dpkg-dev",
170                         "eatmydata", // install it for later steps, even if we're not using it now
171                 )
172         }
173
174         if dev || test || pkg {
175                 pkgs = append(pkgs,
176                         "automake",
177                         "bison",
178                         "bsdmainutils",
179                         "build-essential",
180                         "cadaver",
181                         "curl",
182                         "cython3",
183                         "default-jdk-headless",
184                         "default-jre-headless",
185                         "gettext",
186                         "libattr1-dev",
187                         "libffi-dev",
188                         "libfuse-dev",
189                         "libgbm1", // cypress / workbench2 tests
190                         "libgnutls28-dev",
191                         "libpam-dev",
192                         "libpcre3-dev",
193                         "libpq-dev",
194                         "libreadline-dev",
195                         "libssl-dev",
196                         "libxml2-dev",
197                         "libxslt1-dev",
198                         "libyaml-dev",
199                         "linkchecker",
200                         "lsof",
201                         "make",
202                         "net-tools",
203                         "pandoc",
204                         "pkg-config",
205                         "postgresql",
206                         "postgresql-contrib",
207                         "python3-dev",
208                         "python3-venv",
209                         "python3-virtualenv",
210                         "r-base",
211                         "r-cran-testthat",
212                         "r-cran-devtools",
213                         "r-cran-knitr",
214                         "r-cran-markdown",
215                         "r-cran-roxygen2",
216                         "r-cran-xml",
217                         "rsync",
218                         "sudo",
219                         "uuid-dev",
220                         "wget",
221                         "xvfb",
222                         "zlib1g-dev", // services/api
223                 )
224                 if test {
225                         if osv.Debian && osv.Major <= 10 {
226                                 pkgs = append(pkgs, "iceweasel")
227                         } else if osv.Debian && osv.Major >= 11 {
228                                 pkgs = append(pkgs, "firefox-esr")
229                         } else {
230                                 pkgs = append(pkgs, "firefox")
231                         }
232                 }
233                 if dev || test {
234                         pkgs = append(pkgs,
235                                 "libglib2.0-dev", // singularity (conmon)
236                                 "libseccomp-dev", // singularity (seccomp)
237                                 "squashfs-tools", // singularity
238                                 "gnupg")          // docker install recipe
239                 }
240                 switch {
241                 case osv.Debian && osv.Major >= 10,
242                         osv.Ubuntu && osv.Major >= 22:
243                         pkgs = append(pkgs, "g++", "libcurl4", "libcurl4-openssl-dev")
244                 case osv.Debian || osv.Ubuntu:
245                         pkgs = append(pkgs, "g++", "libcurl3", "libcurl3-openssl-dev")
246                 case osv.Centos:
247                         pkgs = append(pkgs, "gcc", "gcc-c++", "libcurl-devel", "postgresql-devel")
248                 }
249                 cmd := exec.CommandContext(ctx, "apt-get")
250                 if inst.EatMyData {
251                         cmd = exec.CommandContext(ctx, "eatmydata", "apt-get")
252                 }
253                 cmd.Args = append(cmd.Args, "install", "--yes", "--no-install-recommends")
254                 cmd.Args = append(cmd.Args, pkgs...)
255                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
256                 cmd.Stdout = stdout
257                 cmd.Stderr = stderr
258                 err = cmd.Run()
259                 if err != nil {
260                         return 1
261                 }
262         }
263
264         if dev || test {
265                 if havedockerversion, err2 := exec.Command("docker", "--version").CombinedOutput(); err2 == nil {
266                         logger.Printf("%s installed, assuming that version is ok", bytes.TrimSuffix(havedockerversion, []byte("\n")))
267                 } else if osv.Debian {
268                         var codename string
269                         switch osv.Major {
270                         case 10:
271                                 codename = "buster"
272                         case 11:
273                                 codename = "bullseye"
274                         case 12:
275                                 codename = "bookworm"
276                         default:
277                                 err = fmt.Errorf("don't know how to install docker-ce for debian %d", osv.Major)
278                                 return 1
279                         }
280                         err = inst.runBash(`
281 rm -f /usr/share/keyrings/docker-archive-keyring.gpg
282 curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
283 echo 'deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian/ `+codename+` stable' | \
284     tee /etc/apt/sources.list.d/docker.list
285 apt-get update
286 DEBIAN_FRONTEND=noninteractive apt-get --yes --no-install-recommends install docker-ce
287 `, stdout, stderr)
288                         if err != nil {
289                                 return 1
290                         }
291                 } else {
292                         err = fmt.Errorf("don't know how to install docker for osversion %v", osv)
293                         return 1
294                 }
295
296                 err = inst.runBash(`
297 key=fs.inotify.max_user_watches
298 min=524288
299 if [[ "$(sysctl --values "${key}")" -lt "${min}" ]]; then
300     sysctl "${key}=${min}"
301     # writing sysctl worked, so we should make it permanent
302     echo "${key}=${min}" | tee -a /etc/sysctl.conf
303     sysctl -p
304 fi
305 `, stdout, stderr)
306                 if err != nil {
307                         err = fmt.Errorf("couldn't set fs.inotify.max_user_watches value. (Is this a docker container? Fix this on the docker host by adding fs.inotify.max_user_watches=524288 to /etc/sysctl.conf and running `sysctl -p`)")
308                         return 1
309                 }
310         }
311
312         os.Mkdir("/var/lib/arvados", 0755)
313         os.Mkdir("/var/lib/arvados/tmp", 0700)
314         if prod || pkg {
315                 u, er := user.Lookup("www-data")
316                 if er != nil {
317                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
318                         return 1
319                 }
320                 uid, _ := strconv.Atoi(u.Uid)
321                 gid, _ := strconv.Atoi(u.Gid)
322                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
323                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
324                 if err != nil {
325                         return 1
326                 }
327         }
328         rubyminorversion := inst.RubyVersion[:strings.LastIndex(inst.RubyVersion, ".")]
329         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+inst.RubyVersion)) {
330                 logger.Print("ruby " + inst.RubyVersion + " already installed")
331         } else {
332                 err = inst.runBash(`
333 rubyversion="`+inst.RubyVersion+`"
334 rubyminorversion="`+rubyminorversion+`"
335 tmp="$(mktemp -d)"
336 trap 'rm -r "${tmp}"' ERR EXIT
337 wget --progress=dot:giga -O- "https://cache.ruby-lang.org/pub/ruby/$rubyminorversion/ruby-$rubyversion.tar.gz" | tar -C "${tmp}" -xzf -
338 cd "${tmp}/ruby-$rubyversion"
339 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
340 make -j8
341 rm -f /var/lib/arvados/bin/erb
342 make install
343 if [[ "$rubyversion" > "3" ]]; then
344   /var/lib/arvados/bin/gem update --no-document --system 3.4.21
345 fi
346 /var/lib/arvados/bin/gem install bundler --no-document
347 `, stdout, stderr)
348                 if err != nil {
349                         return 1
350                 }
351         }
352
353         if !prod {
354                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
355                         logger.Print("go " + goversion + " already installed")
356                 } else {
357                         err = inst.runBash(`
358 cd /tmp
359 rm -rf /var/lib/arvados/go/
360 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
361 ln -sfv /var/lib/arvados/go/bin/* /usr/local/bin/
362 `, stdout, stderr)
363                         if err != nil {
364                                 return 1
365                         }
366                 }
367         }
368
369         if !prod && !pkg {
370                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
371                         logger.Print("phantomjs " + pjsversion + " already installed")
372                 } else {
373                         err = inst.runBash(`
374 PJS=phantomjs-`+pjsversion+`-linux-x86_64
375 wget --progress=dot:giga -O- https://cache.arvados.org/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
376 ln -sfv /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
377 `, stdout, stderr)
378                         if err != nil {
379                                 return 1
380                         }
381                 }
382
383                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
384                         logger.Print("geckodriver " + geckoversion + " already installed")
385                 } else {
386                         err = inst.runBash(`
387 GD=v`+geckoversion+`
388 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
389 ln -sfv /var/lib/arvados/bin/geckodriver /usr/local/bin/
390 `, stdout, stderr)
391                         if err != nil {
392                                 return 1
393                         }
394                 }
395
396                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
397                         logger.Print("gradle " + gradleversion + " already installed")
398                 } else {
399                         err = inst.runBash(`
400 G=`+gradleversion+`
401 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
402 trap "rm ${zip}" ERR
403 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
404 unzip -o -d /var/lib/arvados ${zip}
405 ln -sfv /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
406 rm ${zip}
407 `, stdout, stderr)
408                         if err != nil {
409                                 return 1
410                         }
411                 }
412
413                 if havesingularityversion, err := exec.Command("/var/lib/arvados/bin/singularity", "--version").CombinedOutput(); err == nil && strings.Contains(string(havesingularityversion), inst.SingularityVersion) {
414                         logger.Print("singularity " + inst.SingularityVersion + " already installed")
415                 } else if dev || test {
416                         err = inst.runBash(`
417 S=`+inst.SingularityVersion+`
418 tmp=/var/lib/arvados/tmp/singularity
419 trap "rm -r ${tmp}" ERR EXIT
420 cd /var/lib/arvados/tmp
421 git clone --recurse-submodules https://github.com/sylabs/singularity
422 cd singularity
423 git checkout v${S}
424 ./mconfig --prefix=/var/lib/arvados
425 make -C ./builddir
426 make -C ./builddir install
427 `, stdout, stderr)
428                         if err != nil {
429                                 return 1
430                         }
431                 }
432
433                 err = inst.runBash(`
434 install /usr/bin/nsenter /var/lib/arvados/bin/nsenter
435 setcap "cap_sys_admin+pei cap_sys_chroot+pei" /var/lib/arvados/bin/nsenter
436 `, stdout, stderr)
437                 if err != nil {
438                         return 1
439                 }
440
441                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
442                 // it's installed, locale -a reports it as
443                 // "en_US.utf8".
444                 wantlocale := "en_US.UTF-8"
445                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
446                         logger.Print("locale " + wantlocale + " already installed")
447                 } else {
448                         err = inst.runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
449                         if err != nil {
450                                 return 1
451                         }
452                 }
453
454                 var pgc struct {
455                         Version       string
456                         Cluster       string
457                         Port          int
458                         Status        string
459                         Owner         string
460                         DataDirectory string
461                         LogFile       string
462                 }
463                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
464                         err = fmt.Errorf("pg_lsclusters: %s", err2)
465                         return 1
466                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
467                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
468                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
469                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
470                         return 1
471                 } else if pgc.Status == "online" {
472                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
473                 } else {
474                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
475                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
476                         cmd.Stdout = stdout
477                         cmd.Stderr = stderr
478                         err = cmd.Start()
479                         if err != nil {
480                                 return 1
481                         }
482                         defer func() {
483                                 cmd.Process.Signal(syscall.SIGTERM)
484                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
485                                 cmd.Wait()
486                         }()
487                         err = waitPostgreSQLReady()
488                         if err != nil {
489                                 return 1
490                         }
491                 }
492
493                 if os.Getpid() == 1 {
494                         // We are the init process (presumably in a
495                         // docker container) so although postgresql is
496                         // installed, it's not running, and initdb
497                         // might never have been run.
498                 }
499
500                 var needcoll []string
501                 // If the en_US.UTF-8 locale wasn't installed when
502                 // postgresql initdb ran, it needs to be added
503                 // explicitly before we can use it in our test suite.
504                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
505                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
506                         cmd.Dir = "/"
507                         out, err2 := cmd.CombinedOutput()
508                         if err != nil {
509                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
510                                 return 1
511                         }
512                         if strings.Contains(string(out), "1") {
513                                 logger.Infof("postgresql supports collation %s", collname)
514                         } else {
515                                 needcoll = append(needcoll, collname)
516                         }
517                 }
518                 if len(needcoll) > 0 && os.Getpid() != 1 {
519                         // In order for the CREATE COLLATION statement
520                         // below to work, the locale must have existed
521                         // when PostgreSQL started up. If we're
522                         // running as init, we must have started
523                         // PostgreSQL ourselves after installing the
524                         // locales. Otherwise, it might need a
525                         // restart, so we attempt to restart it with
526                         // systemd.
527                         if err = inst.runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
528                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
529                         } else if err = waitPostgreSQLReady(); err != nil {
530                                 return 1
531                         }
532                 }
533                 for _, collname := range needcoll {
534                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
535                         cmd.Stdout = stdout
536                         cmd.Stderr = stderr
537                         cmd.Dir = "/"
538                         err = cmd.Run()
539                         if err != nil {
540                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
541                                 return 1
542                         }
543                 }
544
545                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
546                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
547                 cmd.Dir = "/"
548                 if err := cmd.Run(); err == nil {
549                         logger.Print("arvados role exists; superuser privileges added, password updated")
550                 } else {
551                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
552                         cmd.Dir = "/"
553                         cmd.Stdout = stdout
554                         cmd.Stderr = stderr
555                         err = cmd.Run()
556                         if err != nil {
557                                 return 1
558                         }
559                 }
560         }
561
562         if !prod {
563                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == nodejsversion+"\n" {
564                         logger.Print("nodejs " + nodejsversion + " already installed")
565                 } else {
566                         err = inst.runBash(`
567 NJS=`+nodejsversion+`
568 rm -rf /var/lib/arvados/node-*-linux-x64
569 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
570 ln -sfv /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
571 `, stdout, stderr)
572                         if err != nil {
573                                 return 1
574                         }
575                 }
576
577                 if haveyarnversion, err := exec.Command("/usr/local/bin/yarn", "--version").CombinedOutput(); err == nil && len(haveyarnversion) > 0 {
578                         logger.Print("yarn " + strings.TrimSpace(string(haveyarnversion)) + " already installed")
579                 } else {
580                         err = inst.runBash(`
581 npm install -g yarn
582 ln -sfv /var/lib/arvados/node-`+nodejsversion+`-linux-x64/bin/{yarn,yarnpkg} /usr/local/bin/
583 `, stdout, stderr)
584                         if err != nil {
585                                 return 1
586                         }
587                 }
588         }
589
590         if prod || pkg {
591                 // Install Go programs to /var/lib/arvados/bin/
592                 for _, srcdir := range []string{
593                         "cmd/arvados-client",
594                         "cmd/arvados-server",
595                 } {
596                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
597                         // -buildvcs=false here avoids a fatal "error
598                         // obtaining VCS status" when git refuses to
599                         // run (for example) as root in a docker
600                         // container using a non-root-owned git tree
601                         // mounted from the host -- as in
602                         // "arvados-package build".
603                         cmd := exec.Command("go", "install", "-buildvcs=false",
604                                 "-ldflags", "-s -w"+
605                                         " -X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+
606                                         " -X git.arvados.org/arvados.git/lib/cmd.commit="+inst.Commit)
607                         cmd.Env = append(cmd.Env, os.Environ()...)
608                         cmd.Env = append(cmd.Env, "GOBIN=/var/lib/arvados/bin")
609                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
610                         cmd.Stdout = stdout
611                         cmd.Stderr = stderr
612                         err = cmd.Run()
613                         if err != nil {
614                                 return 1
615                         }
616                 }
617
618                 // Copy assets from source tree to /var/lib/arvados/share
619                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
620                 cmd.Stdout = stdout
621                 cmd.Stderr = stderr
622                 err = cmd.Run()
623                 if err != nil {
624                         return 1
625                 }
626
627                 // Install python SDK and arv-mount in
628                 // /var/lib/arvados/lib/python.
629                 //
630                 // setup.py writes a file in the source directory in
631                 // order to include the version number in the package
632                 // itself.  We don't want to write to the source tree
633                 // (in "arvados-package" context it's mounted
634                 // readonly) so we run setup.py in a temporary copy of
635                 // the source dir.
636                 if err = inst.runBash(`
637 v=/var/lib/arvados/lib/python
638 tmp=/var/lib/arvados/tmp/python
639 python3 -m venv "$v"
640 . "$v/bin/activate"
641 pip3 install --no-cache-dir 'setuptools>=68' 'pip>=20'
642 export ARVADOS_BUILDING_VERSION="`+inst.PackageVersion+`"
643 for src in "`+inst.SourcePath+`/sdk/python" "`+inst.SourcePath+`/services/fuse"; do
644   rsync -a --delete-after "$src/" "$tmp/"
645   env -C "$tmp" python3 setup.py build
646   pip3 install "$tmp"
647   rm -rf "$tmp"
648 done
649 `, stdout, stderr); err != nil {
650                         return 1
651                 }
652
653                 // Install RailsAPI to /var/lib/arvados/railsapi/
654                 fmt.Fprintln(stderr, "building railsapi...")
655                 cmd = exec.Command("rsync",
656                         "-a", "--no-owner", "--no-group", "--delete-after", "--delete-excluded",
657                         "--exclude", "/coverage",
658                         "--exclude", "/log",
659                         "--exclude", "/node_modules",
660                         "--exclude", "/tmp",
661                         "--exclude", "/public/assets",
662                         "--exclude", "/vendor",
663                         "--exclude", "/config/environments",
664                         "./", "/var/lib/arvados/railsapi/")
665                 cmd.Dir = filepath.Join(inst.SourcePath, "services", "api")
666                 cmd.Stdout = stdout
667                 cmd.Stderr = stderr
668                 err = cmd.Run()
669                 if err != nil {
670                         return 1
671                 }
672                 for _, cmdline := range [][]string{
673                         {"mkdir", "-p", "log", "public/assets", "tmp", "vendor", ".bundle", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger"},
674                         {"touch", "log/production.log"},
675                         {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger", "log", "tmp", "vendor", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
676                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:" + inst.BundlerVersion},
677                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "deployment", "true"},
678                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "path", "/var/www/.gem"},
679                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "without", "development test diagnostics performance"},
680                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--jobs", fmt.Sprintf("%d", runtime.NumCPU())},
681
682                         {"chown", "www-data:www-data", ".", "public/assets"},
683                         // {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "system", "true"},
684                         {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "npm:install"},
685                         {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "assets:precompile"},
686                         {"chown", "root:root", "."},
687                         {"chown", "-R", "root:root", "public/assets", "vendor"},
688
689                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
690                         {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
691                 } {
692                         if cmdline[len(cmdline)-2] == "rake" {
693                                 continue
694                         }
695                         cmd = exec.Command(cmdline[0], cmdline[1:]...)
696                         cmd.Dir = "/var/lib/arvados/railsapi"
697                         cmd.Stdout = stdout
698                         cmd.Stderr = stderr
699                         fmt.Fprintf(stderr, "... %s\n", cmd.Args)
700                         err = cmd.Run()
701                         if err != nil {
702                                 return 1
703                         }
704                 }
705                 cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
706                 cmd.Dir = "/var/lib/arvados/railsapi"
707                 cmd.Stdout = stdout
708                 cmd.Stderr = stderr
709                 err = cmd.Run()
710                 if err != nil && !strings.Contains(err.Error(), "exit status 2") {
711                         // Exit code 2 indicates there were warnings (like
712                         // "other passenger installations have been detected",
713                         // which we can't expect to avoid) but no errors.
714                         // Other non-zero exit codes (1, 9) indicate errors.
715                         return 1
716                 }
717
718                 // Install workbench2 app to
719                 // /var/lib/arvados/workbench2/.
720                 //
721                 // We copy the source tree from the (possibly
722                 // readonly) source tree into a temp dir because `yarn
723                 // build` writes to {source-tree}/build/. When we
724                 // upgrade to react-scripts >= 4.0.2 we may be able to
725                 // build from the source dir and write directly to the
726                 // final destination (using
727                 // YARN_INSTALL_STATE_PATH=/dev/null
728                 // BUILD_PATH=/var/lib/arvados/workbench2) instead of
729                 // using two rsync steps here.
730                 if err = inst.runBash(`
731 src="`+inst.SourcePath+`/services/workbench2"
732 tmp=/var/lib/arvados/tmp/workbench2
733 trap "rm -r ${tmp}" ERR EXIT
734 dst=/var/lib/arvados/workbench2
735 rsync -a --delete-after "$src/" "$tmp/"
736 env -C "$tmp" VERSION="`+inst.PackageVersion+`" BUILD_NUMBER=1 GIT_COMMIT="`+inst.Commit[:9]+`" yarn build
737 rsync -a --delete-after "$tmp/build/" "$dst/"
738 `, stdout, stderr); err != nil {
739                         return 1
740                 }
741
742                 // Install arvados-cli gem (binaries go in
743                 // /var/lib/arvados/bin)
744                 if err = inst.runBash(`
745 /var/lib/arvados/bin/gem install --conservative --no-document arvados-cli
746 `, stdout, stderr); err != nil {
747                         return 1
748                 }
749
750                 err = os.WriteFile("/lib/systemd/system/arvados.service", arvadosServiceFile, 0777)
751                 if err != nil {
752                         return 1
753                 }
754                 if prod {
755                         // (fpm will do this for us in the pkg case)
756                         // This is equivalent to "systemd enable", but
757                         // does not depend on the systemctl program
758                         // being available:
759                         symlink := "/etc/systemd/system/multi-user.target.wants/arvados.service"
760                         err = os.Remove(symlink)
761                         if err != nil && !errors.Is(err, os.ErrNotExist) {
762                                 return 1
763                         }
764                         err = os.Symlink("/lib/systemd/system/arvados.service", symlink)
765                         if err != nil {
766                                 return 1
767                         }
768                 }
769
770                 // Add symlinks in /usr/bin for user-facing programs
771                 for _, srcdst := range [][]string{
772                         // go
773                         {"bin/arvados-client"},
774                         {"bin/arvados-client", "arv"},
775                         {"bin/arvados-server"},
776                         // sdk/cli
777                         {"bin/arv", "arv-ruby"},
778                         {"bin/arv-tag"},
779                         // sdk/python
780                         {"lib/python/bin/arv-copy"},
781                         {"lib/python/bin/arv-federation-migrate"},
782                         {"lib/python/bin/arv-get"},
783                         {"lib/python/bin/arv-keepdocker"},
784                         {"lib/python/bin/arv-ls"},
785                         {"lib/python/bin/arv-migrate-docker19"},
786                         {"lib/python/bin/arv-normalize"},
787                         {"lib/python/bin/arv-put"},
788                         {"lib/python/bin/arv-ws"},
789                         // services/fuse
790                         {"lib/python/bin/arv-mount"},
791                 } {
792                         src := "/var/lib/arvados/" + srcdst[0]
793                         if _, err = os.Stat(src); err != nil {
794                                 return 1
795                         }
796                         dst := srcdst[len(srcdst)-1]
797                         _, dst = filepath.Split(dst)
798                         dst = "/usr/bin/" + dst
799                         err = os.Remove(dst)
800                         if err != nil && !errors.Is(err, os.ErrNotExist) {
801                                 return 1
802                         }
803                         err = os.Symlink(src, dst)
804                         if err != nil {
805                                 return 1
806                         }
807                 }
808         }
809
810         return 0
811 }
812
813 type osversion struct {
814         Debian bool
815         Ubuntu bool
816         Centos bool
817         Major  int
818 }
819
820 func identifyOS() (osversion, error) {
821         var osv osversion
822         f, err := os.Open("/etc/os-release")
823         if err != nil {
824                 return osv, err
825         }
826         defer f.Close()
827
828         kv := map[string]string{}
829         scanner := bufio.NewScanner(f)
830         for scanner.Scan() {
831                 line := strings.TrimSpace(scanner.Text())
832                 if strings.HasPrefix(line, "#") {
833                         continue
834                 }
835                 toks := strings.SplitN(line, "=", 2)
836                 if len(toks) != 2 {
837                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
838                 }
839                 k := toks[0]
840                 v := strings.Trim(toks[1], `"`)
841                 if v == toks[1] {
842                         v = strings.Trim(v, `'`)
843                 }
844                 kv[k] = v
845         }
846         if err = scanner.Err(); err != nil {
847                 return osv, err
848         }
849         switch kv["ID"] {
850         case "ubuntu":
851                 osv.Ubuntu = true
852         case "debian":
853                 osv.Debian = true
854         case "centos":
855                 osv.Centos = true
856         default:
857                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
858         }
859         vstr := kv["VERSION_ID"]
860         if i := strings.Index(vstr, "."); i > 0 {
861                 vstr = vstr[:i]
862         }
863         osv.Major, err = strconv.Atoi(vstr)
864         if err != nil {
865                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
866         }
867         return osv, nil
868 }
869
870 func waitPostgreSQLReady() error {
871         for deadline := time.Now().Add(10 * time.Second); ; {
872                 output, err := exec.Command("pg_isready").CombinedOutput()
873                 if err == nil {
874                         return nil
875                 } else if time.Now().After(deadline) {
876                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
877                 } else {
878                         time.Sleep(time.Second)
879                 }
880         }
881 }
882
883 func (inst *installCommand) runBash(script string, stdout, stderr io.Writer) error {
884         cmd := exec.Command("bash", "-")
885         if inst.EatMyData {
886                 cmd = exec.Command("eatmydata", "bash", "-")
887         }
888         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
889         cmd.Stdout = stdout
890         cmd.Stderr = stderr
891         return cmd.Run()
892 }
893
894 func prodpkgs(osv osversion) []string {
895         pkgs := []string{
896                 "ca-certificates",
897                 "curl",
898                 "fuse",
899                 "git",
900                 "gitolite3",
901                 "graphviz",
902                 "haveged",
903                 "libcurl3-gnutls",
904                 "libxslt1.1",
905                 "nginx",
906                 "python3",
907                 "sudo",
908         }
909         if osv.Debian || osv.Ubuntu {
910                 if osv.Debian && osv.Major == 8 {
911                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
912                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
913                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
914                 }
915                 return append(pkgs,
916                         "mime-support", // keep-web
917                 )
918         } else if osv.Centos {
919                 return append(pkgs,
920                         "fuse-libs", // services/fuse
921                         "mailcap",   // keep-web
922                 )
923         } else {
924                 panic("os version not supported")
925         }
926 }
927
928 func ProductionDependencies() ([]string, error) {
929         osv, err := identifyOS()
930         if err != nil {
931                 return nil, err
932         }
933         return prodpkgs(osv), nil
934 }