19745: Update ruby, node, wb2.
[arvados.git] / lib / install / deps.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package install
6
7 import (
8         "bufio"
9         "bytes"
10         "context"
11         _ "embed"
12         "errors"
13         "flag"
14         "fmt"
15         "io"
16         "os"
17         "os/exec"
18         "os/user"
19         "path/filepath"
20         "runtime"
21         "strconv"
22         "strings"
23         "syscall"
24         "time"
25
26         "git.arvados.org/arvados.git/lib/cmd"
27         "git.arvados.org/arvados.git/sdk/go/ctxlog"
28         "github.com/lib/pq"
29 )
30
31 var Command cmd.Handler = &installCommand{}
32
33 const goversion = "1.18.8"
34
35 const (
36         rubyversion             = "2.7.6"
37         bundlerversion          = "2.2.19"
38         singularityversion      = "3.9.9"
39         pjsversion              = "1.9.8"
40         geckoversion            = "0.24.0"
41         gradleversion           = "5.3.1"
42         nodejsversion           = "v12.22.12"
43         devtestDatabasePassword = "insecure_arvados_test"
44         workbench2version       = "e30e54d674c95ee15e296c71e471c1555bdc5a38" // 2.4.3
45 )
46
47 //go:embed arvados.service
48 var arvadosServiceFile []byte
49
50 type installCommand struct {
51         ClusterType    string
52         SourcePath     string
53         PackageVersion string
54         EatMyData      bool
55 }
56
57 func (inst *installCommand) RunCommand(prog string, args []string, stdin io.Reader, stdout, stderr io.Writer) int {
58         logger := ctxlog.New(stderr, "text", "info")
59         ctx := ctxlog.Context(context.Background(), logger)
60         ctx, cancel := context.WithCancel(ctx)
61         defer cancel()
62
63         var err error
64         defer func() {
65                 if err != nil {
66                         logger.WithError(err).Info("exiting")
67                 }
68         }()
69
70         flags := flag.NewFlagSet(prog, flag.ContinueOnError)
71         flags.SetOutput(stderr)
72         versionFlag := flags.Bool("version", false, "Write version information to stdout and exit 0")
73         flags.StringVar(&inst.ClusterType, "type", "production", "cluster `type`: development, test, production, or package")
74         flags.StringVar(&inst.SourcePath, "source", "/arvados", "source tree location (required for -type=package)")
75         flags.StringVar(&inst.PackageVersion, "package-version", "0.0.0", "version string to embed in executable files")
76         flags.BoolVar(&inst.EatMyData, "eatmydata", false, "use eatmydata to speed up install")
77
78         if ok, code := cmd.ParseFlags(flags, prog, args, "", stderr); !ok {
79                 return code
80         } else if *versionFlag {
81                 return cmd.Version.RunCommand(prog, args, stdin, stdout, stderr)
82         }
83
84         var dev, test, prod, pkg bool
85         switch inst.ClusterType {
86         case "development":
87                 dev = true
88         case "test":
89                 test = true
90         case "production":
91                 prod = true
92         case "package":
93                 pkg = true
94         default:
95                 err = fmt.Errorf("invalid cluster type %q (must be 'development', 'test', 'production', or 'package')", inst.ClusterType)
96                 return 2
97         }
98
99         if prod {
100                 err = errors.New("production install is not yet implemented")
101                 return 1
102         }
103
104         osv, err := identifyOS()
105         if err != nil {
106                 return 1
107         }
108
109         listdir, err := os.Open("/var/lib/apt/lists")
110         if err != nil {
111                 logger.Warnf("error while checking whether to run apt-get update: %s", err)
112         } else if names, _ := listdir.Readdirnames(1); len(names) == 0 {
113                 // Special case for a base docker image where the
114                 // package cache has been deleted and all "apt-get
115                 // install" commands will fail unless we fetch repos.
116                 cmd := exec.CommandContext(ctx, "apt-get", "update")
117                 cmd.Stdout = stdout
118                 cmd.Stderr = stderr
119                 err = cmd.Run()
120                 if err != nil {
121                         return 1
122                 }
123         }
124
125         if inst.EatMyData {
126                 cmd := exec.CommandContext(ctx, "apt-get", "install", "--yes", "--no-install-recommends", "eatmydata")
127                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
128                 cmd.Stdout = stdout
129                 cmd.Stderr = stderr
130                 err = cmd.Run()
131                 if err != nil {
132                         return 1
133                 }
134         }
135
136         pkgs := prodpkgs(osv)
137
138         if pkg {
139                 pkgs = append(pkgs,
140                         "dpkg-dev",
141                         "eatmydata", // install it for later steps, even if we're not using it now
142                 )
143         }
144
145         if dev || test || pkg {
146                 pkgs = append(pkgs,
147                         "automake",
148                         "bison",
149                         "bsdmainutils",
150                         "build-essential",
151                         "cadaver",
152                         "curl",
153                         "cython3",
154                         "default-jdk-headless",
155                         "default-jre-headless",
156                         "gettext",
157                         "libattr1-dev",
158                         "libcrypt-ssleay-perl",
159                         "libfuse-dev",
160                         "libgbm1", // cypress / workbench2 tests
161                         "libgnutls28-dev",
162                         "libjson-perl",
163                         "libpam-dev",
164                         "libpcre3-dev",
165                         "libpq-dev",
166                         "libreadline-dev",
167                         "libssl-dev",
168                         "libwww-perl",
169                         "libxml2-dev",
170                         "libxslt1-dev",
171                         "linkchecker",
172                         "lsof",
173                         "make",
174                         "net-tools",
175                         "pandoc",
176                         "pkg-config",
177                         "postgresql",
178                         "postgresql-contrib",
179                         "python3-dev",
180                         "python3-venv",
181                         "python3-virtualenv",
182                         "r-base",
183                         "r-cran-testthat",
184                         "r-cran-devtools",
185                         "r-cran-knitr",
186                         "r-cran-markdown",
187                         "r-cran-roxygen2",
188                         "r-cran-xml",
189                         "rsync",
190                         "sudo",
191                         "uuid-dev",
192                         "wget",
193                         "xvfb",
194                         "zlib1g-dev", // services/api
195                 )
196                 if test {
197                         if osv.Debian && osv.Major <= 10 {
198                                 pkgs = append(pkgs, "iceweasel")
199                         } else {
200                                 pkgs = append(pkgs, "firefox")
201                         }
202                 }
203                 if dev || test {
204                         pkgs = append(pkgs, "squashfs-tools") // for singularity
205                         pkgs = append(pkgs, "gnupg")          // for docker install recipe
206                 }
207                 switch {
208                 case osv.Debian && osv.Major >= 11:
209                         pkgs = append(pkgs, "g++", "libcurl4", "libcurl4-openssl-dev", "perl-modules-5.32")
210                 case osv.Debian && osv.Major >= 10:
211                         pkgs = append(pkgs, "g++", "libcurl4", "libcurl4-openssl-dev", "perl-modules")
212                 case osv.Debian || osv.Ubuntu:
213                         pkgs = append(pkgs, "g++", "libcurl3", "libcurl3-openssl-dev", "perl-modules")
214                 case osv.Centos:
215                         pkgs = append(pkgs, "gcc", "gcc-c++", "libcurl-devel", "postgresql-devel")
216                 }
217                 cmd := exec.CommandContext(ctx, "apt-get")
218                 if inst.EatMyData {
219                         cmd = exec.CommandContext(ctx, "eatmydata", "apt-get")
220                 }
221                 cmd.Args = append(cmd.Args, "install", "--yes", "--no-install-recommends")
222                 cmd.Args = append(cmd.Args, pkgs...)
223                 cmd.Env = append(os.Environ(), "DEBIAN_FRONTEND=noninteractive")
224                 cmd.Stdout = stdout
225                 cmd.Stderr = stderr
226                 err = cmd.Run()
227                 if err != nil {
228                         return 1
229                 }
230         }
231
232         if dev || test {
233                 if havedockerversion, err := exec.Command("docker", "--version").CombinedOutput(); err == nil {
234                         logger.Printf("%s installed, assuming that version is ok", bytes.TrimSuffix(havedockerversion, []byte("\n")))
235                 } else if osv.Debian {
236                         var codename string
237                         switch osv.Major {
238                         case 10:
239                                 codename = "buster"
240                         case 11:
241                                 codename = "bullseye"
242                         default:
243                                 err = fmt.Errorf("don't know how to install docker-ce for debian %d", osv.Major)
244                                 return 1
245                         }
246                         err = inst.runBash(`
247 rm -f /usr/share/keyrings/docker-archive-keyring.gpg
248 curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
249 echo 'deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian/ `+codename+` stable' | \
250     tee /etc/apt/sources.list.d/docker.list
251 apt-get update
252 DEBIAN_FRONTEND=noninteractive apt-get --yes --no-install-recommends install docker-ce
253 `, stdout, stderr)
254                         if err != nil {
255                                 return 1
256                         }
257                 } else {
258                         err = fmt.Errorf("don't know how to install docker for osversion %v", osv)
259                         return 1
260                 }
261         }
262
263         os.Mkdir("/var/lib/arvados", 0755)
264         os.Mkdir("/var/lib/arvados/tmp", 0700)
265         if prod || pkg {
266                 u, er := user.Lookup("www-data")
267                 if er != nil {
268                         err = fmt.Errorf("user.Lookup(%q): %w", "www-data", er)
269                         return 1
270                 }
271                 uid, _ := strconv.Atoi(u.Uid)
272                 gid, _ := strconv.Atoi(u.Gid)
273                 os.Mkdir("/var/lib/arvados/wwwtmp", 0700)
274                 err = os.Chown("/var/lib/arvados/wwwtmp", uid, gid)
275                 if err != nil {
276                         return 1
277                 }
278         }
279         rubymajorversion := rubyversion[:strings.LastIndex(rubyversion, ".")]
280         if haverubyversion, err := exec.Command("/var/lib/arvados/bin/ruby", "-v").CombinedOutput(); err == nil && bytes.HasPrefix(haverubyversion, []byte("ruby "+rubyversion)) {
281                 logger.Print("ruby " + rubyversion + " already installed")
282         } else {
283                 err = inst.runBash(`
284 tmp="$(mktemp -d)"
285 trap 'rm -r "${tmp}"' ERR EXIT
286 wget --progress=dot:giga -O- https://cache.ruby-lang.org/pub/ruby/`+rubymajorversion+`/ruby-`+rubyversion+`.tar.gz | tar -C "${tmp}" -xzf -
287 cd "${tmp}/ruby-`+rubyversion+`"
288 ./configure --disable-install-static-library --enable-shared --disable-install-doc --prefix /var/lib/arvados
289 make -j8
290 make install
291 /var/lib/arvados/bin/gem install bundler --no-document
292 `, stdout, stderr)
293                 if err != nil {
294                         return 1
295                 }
296         }
297
298         if !prod {
299                 if havegoversion, err := exec.Command("/usr/local/bin/go", "version").CombinedOutput(); err == nil && bytes.HasPrefix(havegoversion, []byte("go version go"+goversion+" ")) {
300                         logger.Print("go " + goversion + " already installed")
301                 } else {
302                         err = inst.runBash(`
303 cd /tmp
304 rm -rf /var/lib/arvados/go/
305 wget --progress=dot:giga -O- https://storage.googleapis.com/golang/go`+goversion+`.linux-amd64.tar.gz | tar -C /var/lib/arvados -xzf -
306 ln -sfv /var/lib/arvados/go/bin/* /usr/local/bin/
307 `, stdout, stderr)
308                         if err != nil {
309                                 return 1
310                         }
311                 }
312         }
313
314         if !prod && !pkg {
315                 if havepjsversion, err := exec.Command("/usr/local/bin/phantomjs", "--version").CombinedOutput(); err == nil && string(havepjsversion) == "1.9.8\n" {
316                         logger.Print("phantomjs " + pjsversion + " already installed")
317                 } else {
318                         err = inst.runBash(`
319 PJS=phantomjs-`+pjsversion+`-linux-x86_64
320 wget --progress=dot:giga -O- https://cache.arvados.org/$PJS.tar.bz2 | tar -C /var/lib/arvados -xjf -
321 ln -sfv /var/lib/arvados/$PJS/bin/phantomjs /usr/local/bin/
322 `, stdout, stderr)
323                         if err != nil {
324                                 return 1
325                         }
326                 }
327
328                 if havegeckoversion, err := exec.Command("/usr/local/bin/geckodriver", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegeckoversion), " "+geckoversion+" ") {
329                         logger.Print("geckodriver " + geckoversion + " already installed")
330                 } else {
331                         err = inst.runBash(`
332 GD=v`+geckoversion+`
333 wget --progress=dot:giga -O- https://github.com/mozilla/geckodriver/releases/download/$GD/geckodriver-$GD-linux64.tar.gz | tar -C /var/lib/arvados/bin -xzf - geckodriver
334 ln -sfv /var/lib/arvados/bin/geckodriver /usr/local/bin/
335 `, stdout, stderr)
336                         if err != nil {
337                                 return 1
338                         }
339                 }
340
341                 if havegradleversion, err := exec.Command("/usr/local/bin/gradle", "--version").CombinedOutput(); err == nil && strings.Contains(string(havegradleversion), "Gradle "+gradleversion+"\n") {
342                         logger.Print("gradle " + gradleversion + " already installed")
343                 } else {
344                         err = inst.runBash(`
345 G=`+gradleversion+`
346 zip=/var/lib/arvados/tmp/gradle-${G}-bin.zip
347 trap "rm ${zip}" ERR
348 wget --progress=dot:giga -O${zip} https://services.gradle.org/distributions/gradle-${G}-bin.zip
349 unzip -o -d /var/lib/arvados ${zip}
350 ln -sfv /var/lib/arvados/gradle-${G}/bin/gradle /usr/local/bin/
351 rm ${zip}
352 `, stdout, stderr)
353                         if err != nil {
354                                 return 1
355                         }
356                 }
357
358                 if havesingularityversion, err := exec.Command("/var/lib/arvados/bin/singularity", "--version").CombinedOutput(); err == nil && strings.Contains(string(havesingularityversion), singularityversion) {
359                         logger.Print("singularity " + singularityversion + " already installed")
360                 } else if dev || test {
361                         err = inst.runBash(`
362 S=`+singularityversion+`
363 tmp=/var/lib/arvados/tmp/singularity
364 trap "rm -r ${tmp}" ERR EXIT
365 cd /var/lib/arvados/tmp
366 git clone https://github.com/sylabs/singularity
367 cd singularity
368 git checkout v${S}
369 ./mconfig --prefix=/var/lib/arvados
370 make -C ./builddir
371 make -C ./builddir install
372 `, stdout, stderr)
373                         if err != nil {
374                                 return 1
375                         }
376                 }
377
378                 err = inst.runBash(`
379 install /usr/bin/nsenter /var/lib/arvados/bin/nsenter
380 setcap "cap_sys_admin+pei cap_sys_chroot+pei" /var/lib/arvados/bin/nsenter
381 `, stdout, stderr)
382                 if err != nil {
383                         return 1
384                 }
385
386                 // The entry in /etc/locale.gen is "en_US.UTF-8"; once
387                 // it's installed, locale -a reports it as
388                 // "en_US.utf8".
389                 wantlocale := "en_US.UTF-8"
390                 if havelocales, err := exec.Command("locale", "-a").CombinedOutput(); err == nil && bytes.Contains(havelocales, []byte(strings.Replace(wantlocale+"\n", "UTF-", "utf", 1))) {
391                         logger.Print("locale " + wantlocale + " already installed")
392                 } else {
393                         err = inst.runBash(`sed -i 's/^# *\(`+wantlocale+`\)/\1/' /etc/locale.gen && locale-gen`, stdout, stderr)
394                         if err != nil {
395                                 return 1
396                         }
397                 }
398
399                 var pgc struct {
400                         Version       string
401                         Cluster       string
402                         Port          int
403                         Status        string
404                         Owner         string
405                         DataDirectory string
406                         LogFile       string
407                 }
408                 if pgLsclusters, err2 := exec.Command("pg_lsclusters", "--no-header").CombinedOutput(); err2 != nil {
409                         err = fmt.Errorf("pg_lsclusters: %s", err2)
410                         return 1
411                 } else if pgclusters := strings.Split(strings.TrimSpace(string(pgLsclusters)), "\n"); len(pgclusters) != 1 {
412                         logger.Warnf("pg_lsclusters returned %d postgresql clusters -- skipping postgresql initdb/startup, hope that's ok", len(pgclusters))
413                 } else if _, err = fmt.Sscanf(pgclusters[0], "%s %s %d %s %s %s %s", &pgc.Version, &pgc.Cluster, &pgc.Port, &pgc.Status, &pgc.Owner, &pgc.DataDirectory, &pgc.LogFile); err != nil {
414                         err = fmt.Errorf("error parsing pg_lsclusters output: %s", err)
415                         return 1
416                 } else if pgc.Status == "online" {
417                         logger.Infof("postgresql cluster %s-%s is online", pgc.Version, pgc.Cluster)
418                 } else {
419                         logger.Infof("postgresql cluster %s-%s is %s; trying to start", pgc.Version, pgc.Cluster, pgc.Status)
420                         cmd := exec.Command("pg_ctlcluster", "--foreground", pgc.Version, pgc.Cluster, "start")
421                         cmd.Stdout = stdout
422                         cmd.Stderr = stderr
423                         err = cmd.Start()
424                         if err != nil {
425                                 return 1
426                         }
427                         defer func() {
428                                 cmd.Process.Signal(syscall.SIGTERM)
429                                 logger.Info("sent SIGTERM; waiting for postgres to shut down")
430                                 cmd.Wait()
431                         }()
432                         err = waitPostgreSQLReady()
433                         if err != nil {
434                                 return 1
435                         }
436                 }
437
438                 if os.Getpid() == 1 {
439                         // We are the init process (presumably in a
440                         // docker container) so although postgresql is
441                         // installed, it's not running, and initdb
442                         // might never have been run.
443                 }
444
445                 var needcoll []string
446                 // If the en_US.UTF-8 locale wasn't installed when
447                 // postgresql initdb ran, it needs to be added
448                 // explicitly before we can use it in our test suite.
449                 for _, collname := range []string{"en_US", "en_US.UTF-8"} {
450                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-t", "-c", "SELECT 1 FROM pg_catalog.pg_collation WHERE collname='"+collname+"' AND collcollate IN ('en_US.UTF-8', 'en_US.utf8')")
451                         cmd.Dir = "/"
452                         out, err2 := cmd.CombinedOutput()
453                         if err != nil {
454                                 err = fmt.Errorf("error while checking postgresql collations: %s", err2)
455                                 return 1
456                         }
457                         if strings.Contains(string(out), "1") {
458                                 logger.Infof("postgresql supports collation %s", collname)
459                         } else {
460                                 needcoll = append(needcoll, collname)
461                         }
462                 }
463                 if len(needcoll) > 0 && os.Getpid() != 1 {
464                         // In order for the CREATE COLLATION statement
465                         // below to work, the locale must have existed
466                         // when PostgreSQL started up. If we're
467                         // running as init, we must have started
468                         // PostgreSQL ourselves after installing the
469                         // locales. Otherwise, it might need a
470                         // restart, so we attempt to restart it with
471                         // systemd.
472                         if err = inst.runBash(`sudo systemctl restart postgresql`, stdout, stderr); err != nil {
473                                 logger.Warn("`systemctl restart postgresql` failed; hoping postgresql does not need to be restarted")
474                         } else if err = waitPostgreSQLReady(); err != nil {
475                                 return 1
476                         }
477                 }
478                 for _, collname := range needcoll {
479                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE COLLATION \""+collname+"\" (LOCALE = \"en_US.UTF-8\")")
480                         cmd.Stdout = stdout
481                         cmd.Stderr = stderr
482                         cmd.Dir = "/"
483                         err = cmd.Run()
484                         if err != nil {
485                                 err = fmt.Errorf("error adding postgresql collation %s: %s", collname, err)
486                                 return 1
487                         }
488                 }
489
490                 withstuff := "WITH LOGIN SUPERUSER ENCRYPTED PASSWORD " + pq.QuoteLiteral(devtestDatabasePassword)
491                 cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "ALTER ROLE arvados "+withstuff)
492                 cmd.Dir = "/"
493                 if err := cmd.Run(); err == nil {
494                         logger.Print("arvados role exists; superuser privileges added, password updated")
495                 } else {
496                         cmd := exec.Command("sudo", "-u", "postgres", "psql", "-c", "CREATE ROLE arvados "+withstuff)
497                         cmd.Dir = "/"
498                         cmd.Stdout = stdout
499                         cmd.Stderr = stderr
500                         err = cmd.Run()
501                         if err != nil {
502                                 return 1
503                         }
504                 }
505         }
506
507         if !prod {
508                 if havenodejsversion, err := exec.Command("/usr/local/bin/node", "--version").CombinedOutput(); err == nil && string(havenodejsversion) == nodejsversion+"\n" {
509                         logger.Print("nodejs " + nodejsversion + " already installed")
510                 } else {
511                         err = inst.runBash(`
512 NJS=`+nodejsversion+`
513 rm -rf /var/lib/arvados/node-*-linux-x64
514 wget --progress=dot:giga -O- https://nodejs.org/dist/${NJS}/node-${NJS}-linux-x64.tar.xz | sudo tar -C /var/lib/arvados -xJf -
515 ln -sfv /var/lib/arvados/node-${NJS}-linux-x64/bin/{node,npm} /usr/local/bin/
516 `, stdout, stderr)
517                         if err != nil {
518                                 return 1
519                         }
520                 }
521
522                 if haveyarnversion, err := exec.Command("/usr/local/bin/yarn", "--version").CombinedOutput(); err == nil && len(haveyarnversion) > 0 {
523                         logger.Print("yarn " + strings.TrimSpace(string(haveyarnversion)) + " already installed")
524                 } else {
525                         err = inst.runBash(`
526 npm install -g yarn
527 ln -sfv /var/lib/arvados/node-`+nodejsversion+`-linux-x64/bin/{yarn,yarnpkg} /usr/local/bin/
528 `, stdout, stderr)
529                         if err != nil {
530                                 return 1
531                         }
532                 }
533
534                 if havewb2version, err := exec.Command("git", "--git-dir=/var/lib/arvados/arvados-workbench2/.git", "log", "-n1", "--format=%H").CombinedOutput(); err == nil && string(havewb2version) == workbench2version+"\n" {
535                         logger.Print("workbench2 repo is already at " + workbench2version)
536                 } else {
537                         err = inst.runBash(`
538 V=`+workbench2version+`
539 cd /var/lib/arvados
540 if [[ ! -e arvados-workbench2 ]]; then
541   git clone https://git.arvados.org/arvados-workbench2.git
542   cd arvados-workbench2
543   git checkout $V
544 else
545   cd arvados-workbench2
546   if ! git checkout $V; then
547     git fetch
548     git checkout yarn.lock
549     git checkout $V
550   fi
551 fi
552 rm -rf build
553 `, stdout, stderr)
554                         if err != nil {
555                                 return 1
556                         }
557                 }
558
559                 if err = inst.runBash(`
560 cd /var/lib/arvados/arvados-workbench2
561 yarn install
562 `, stdout, stderr); err != nil {
563                         return 1
564                 }
565         }
566
567         if prod || pkg {
568                 // Install Go programs to /var/lib/arvados/bin/
569                 for _, srcdir := range []string{
570                         "cmd/arvados-client",
571                         "cmd/arvados-server",
572                 } {
573                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
574                         cmd := exec.Command("go", "install", "-ldflags", "-X git.arvados.org/arvados.git/lib/cmd.version="+inst.PackageVersion+" -X main.version="+inst.PackageVersion+" -s -w")
575                         cmd.Env = append(cmd.Env, os.Environ()...)
576                         cmd.Env = append(cmd.Env, "GOBIN=/var/lib/arvados/bin")
577                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
578                         cmd.Stdout = stdout
579                         cmd.Stderr = stderr
580                         err = cmd.Run()
581                         if err != nil {
582                                 return 1
583                         }
584                 }
585
586                 // Copy assets from source tree to /var/lib/arvados/share
587                 cmd := exec.Command("install", "-v", "-t", "/var/lib/arvados/share", filepath.Join(inst.SourcePath, "sdk/python/tests/nginx.conf"))
588                 cmd.Stdout = stdout
589                 cmd.Stderr = stderr
590                 err = cmd.Run()
591                 if err != nil {
592                         return 1
593                 }
594
595                 // Install python SDK and arv-mount in
596                 // /var/lib/arvados/lib/python.
597                 //
598                 // setup.py writes a file in the source directory in
599                 // order to include the version number in the package
600                 // itself.  We don't want to write to the source tree
601                 // (in "arvados-package" context it's mounted
602                 // readonly) so we run setup.py in a temporary copy of
603                 // the source dir.
604                 if err = inst.runBash(`
605 v=/var/lib/arvados/lib/python
606 tmp=/var/lib/arvados/tmp/python
607 python3 -m venv "$v"
608 . "$v/bin/activate"
609 pip3 install --no-cache-dir 'setuptools>=18.5' 'pip>=7'
610 export ARVADOS_BUILDING_VERSION="`+inst.PackageVersion+`"
611 for src in "`+inst.SourcePath+`/sdk/python" "`+inst.SourcePath+`/services/fuse"; do
612   rsync -a --delete-after "$src/" "$tmp/"
613   cd "$tmp"
614   python3 setup.py install
615   cd ..
616   rm -rf "$tmp"
617 done
618 `, stdout, stderr); err != nil {
619                         return 1
620                 }
621
622                 // Install Rails apps to /var/lib/arvados/{railsapi,workbench1}/
623                 for dstdir, srcdir := range map[string]string{
624                         "railsapi":   "services/api",
625                         "workbench1": "apps/workbench",
626                 } {
627                         fmt.Fprintf(stderr, "building %s...\n", srcdir)
628                         cmd := exec.Command("rsync",
629                                 "-a", "--no-owner", "--no-group", "--delete-after", "--delete-excluded",
630                                 "--exclude", "/coverage",
631                                 "--exclude", "/log",
632                                 "--exclude", "/node_modules",
633                                 "--exclude", "/tmp",
634                                 "--exclude", "/public/assets",
635                                 "--exclude", "/vendor",
636                                 "--exclude", "/config/environments",
637                                 "./", "/var/lib/arvados/"+dstdir+"/")
638                         cmd.Dir = filepath.Join(inst.SourcePath, srcdir)
639                         cmd.Stdout = stdout
640                         cmd.Stderr = stderr
641                         err = cmd.Run()
642                         if err != nil {
643                                 return 1
644                         }
645                         for _, cmdline := range [][]string{
646                                 {"mkdir", "-p", "log", "public/assets", "tmp", "vendor", ".bundle", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger"},
647                                 {"touch", "log/production.log"},
648                                 {"chown", "-R", "--from=root", "www-data:www-data", "/var/www/.bundle", "/var/www/.gem", "/var/www/.npm", "/var/www/.passenger", "log", "tmp", "vendor", ".bundle", "Gemfile.lock", "config.ru", "config/environment.rb"},
649                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/gem", "install", "--user", "--conservative", "--no-document", "bundler:" + bundlerversion},
650                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "deployment", "true"},
651                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "path", "/var/www/.gem"},
652                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "without", "development test diagnostics performance"},
653                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "install", "--jobs", fmt.Sprintf("%d", runtime.NumCPU())},
654
655                                 {"chown", "www-data:www-data", ".", "public/assets"},
656                                 // {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "config", "set", "--local", "system", "true"},
657                                 {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "npm:install"},
658                                 {"sudo", "-u", "www-data", "ARVADOS_CONFIG=none", "RAILS_GROUPS=assets", "RAILS_ENV=production", "PATH=/var/lib/arvados/bin:" + os.Getenv("PATH"), "/var/lib/arvados/bin/bundle", "exec", "rake", "assets:precompile"},
659                                 {"chown", "root:root", "."},
660                                 {"chown", "-R", "root:root", "public/assets", "vendor"},
661
662                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "build-native-support"},
663                                 {"sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "install-standalone-runtime"},
664                         } {
665                                 if cmdline[len(cmdline)-2] == "rake" && dstdir != "workbench1" {
666                                         continue
667                                 }
668                                 cmd = exec.Command(cmdline[0], cmdline[1:]...)
669                                 cmd.Dir = "/var/lib/arvados/" + dstdir
670                                 cmd.Stdout = stdout
671                                 cmd.Stderr = stderr
672                                 fmt.Fprintf(stderr, "... %s\n", cmd.Args)
673                                 err = cmd.Run()
674                                 if err != nil {
675                                         return 1
676                                 }
677                         }
678                         cmd = exec.Command("sudo", "-u", "www-data", "/var/lib/arvados/bin/bundle", "exec", "passenger-config", "validate-install")
679                         cmd.Dir = "/var/lib/arvados/" + dstdir
680                         cmd.Stdout = stdout
681                         cmd.Stderr = stderr
682                         err = cmd.Run()
683                         if err != nil && !strings.Contains(err.Error(), "exit status 2") {
684                                 // Exit code 2 indicates there were warnings (like
685                                 // "other passenger installations have been detected",
686                                 // which we can't expect to avoid) but no errors.
687                                 // Other non-zero exit codes (1, 9) indicate errors.
688                                 return 1
689                         }
690                 }
691
692                 // Install workbench2 app to /var/lib/arvados/workbench2/
693                 if err = inst.runBash(`
694 cd /var/lib/arvados/arvados-workbench2
695 VERSION="`+inst.PackageVersion+`" BUILD_NUMBER=1 GIT_COMMIT="`+workbench2version[:9]+`" yarn build
696 rsync -a --delete-after build/ /var/lib/arvados/workbench2/
697 `, stdout, stderr); err != nil {
698                         return 1
699                 }
700
701                 // Install arvados-cli gem (binaries go in
702                 // /var/lib/arvados/bin)
703                 if err = inst.runBash(`
704 /var/lib/arvados/bin/gem install --conservative --no-document arvados-cli
705 `, stdout, stderr); err != nil {
706                         return 1
707                 }
708
709                 err = os.WriteFile("/lib/systemd/system/arvados.service", arvadosServiceFile, 0777)
710                 if err != nil {
711                         return 1
712                 }
713                 if prod {
714                         // (fpm will do this for us in the pkg case)
715                         // This is equivalent to "systemd enable", but
716                         // does not depend on the systemctl program
717                         // being available:
718                         symlink := "/etc/systemd/system/multi-user.target.wants/arvados.service"
719                         err = os.Remove(symlink)
720                         if err != nil && !errors.Is(err, os.ErrNotExist) {
721                                 return 1
722                         }
723                         err = os.Symlink("/lib/systemd/system/arvados.service", symlink)
724                         if err != nil {
725                                 return 1
726                         }
727                 }
728
729                 // Add symlinks in /usr/bin for user-facing programs
730                 for _, srcdst := range [][]string{
731                         // go
732                         {"bin/arvados-client"},
733                         {"bin/arvados-client", "arv"},
734                         {"bin/arvados-server"},
735                         // sdk/cli
736                         {"bin/arv", "arv-ruby"},
737                         {"bin/arv-tag"},
738                         // sdk/python
739                         {"lib/python/bin/arv-copy"},
740                         {"lib/python/bin/arv-federation-migrate"},
741                         {"lib/python/bin/arv-get"},
742                         {"lib/python/bin/arv-keepdocker"},
743                         {"lib/python/bin/arv-ls"},
744                         {"lib/python/bin/arv-migrate-docker19"},
745                         {"lib/python/bin/arv-normalize"},
746                         {"lib/python/bin/arv-put"},
747                         {"lib/python/bin/arv-ws"},
748                         // services/fuse
749                         {"lib/python/bin/arv-mount"},
750                 } {
751                         src := "/var/lib/arvados/" + srcdst[0]
752                         if _, err = os.Stat(src); err != nil {
753                                 return 1
754                         }
755                         dst := srcdst[len(srcdst)-1]
756                         _, dst = filepath.Split(dst)
757                         dst = "/usr/bin/" + dst
758                         err = os.Remove(dst)
759                         if err != nil && !errors.Is(err, os.ErrNotExist) {
760                                 return 1
761                         }
762                         err = os.Symlink(src, dst)
763                         if err != nil {
764                                 return 1
765                         }
766                 }
767         }
768
769         return 0
770 }
771
772 type osversion struct {
773         Debian bool
774         Ubuntu bool
775         Centos bool
776         Major  int
777 }
778
779 func identifyOS() (osversion, error) {
780         var osv osversion
781         f, err := os.Open("/etc/os-release")
782         if err != nil {
783                 return osv, err
784         }
785         defer f.Close()
786
787         kv := map[string]string{}
788         scanner := bufio.NewScanner(f)
789         for scanner.Scan() {
790                 line := strings.TrimSpace(scanner.Text())
791                 if strings.HasPrefix(line, "#") {
792                         continue
793                 }
794                 toks := strings.SplitN(line, "=", 2)
795                 if len(toks) != 2 {
796                         return osv, fmt.Errorf("invalid line in /etc/os-release: %q", line)
797                 }
798                 k := toks[0]
799                 v := strings.Trim(toks[1], `"`)
800                 if v == toks[1] {
801                         v = strings.Trim(v, `'`)
802                 }
803                 kv[k] = v
804         }
805         if err = scanner.Err(); err != nil {
806                 return osv, err
807         }
808         switch kv["ID"] {
809         case "ubuntu":
810                 osv.Ubuntu = true
811         case "debian":
812                 osv.Debian = true
813         case "centos":
814                 osv.Centos = true
815         default:
816                 return osv, fmt.Errorf("unsupported ID in /etc/os-release: %q", kv["ID"])
817         }
818         vstr := kv["VERSION_ID"]
819         if i := strings.Index(vstr, "."); i > 0 {
820                 vstr = vstr[:i]
821         }
822         osv.Major, err = strconv.Atoi(vstr)
823         if err != nil {
824                 return osv, fmt.Errorf("incomprehensible VERSION_ID in /etc/os-release: %q", kv["VERSION_ID"])
825         }
826         return osv, nil
827 }
828
829 func waitPostgreSQLReady() error {
830         for deadline := time.Now().Add(10 * time.Second); ; {
831                 output, err := exec.Command("pg_isready").CombinedOutput()
832                 if err == nil {
833                         return nil
834                 } else if time.Now().After(deadline) {
835                         return fmt.Errorf("timed out waiting for pg_isready (%q)", output)
836                 } else {
837                         time.Sleep(time.Second)
838                 }
839         }
840 }
841
842 func (inst *installCommand) runBash(script string, stdout, stderr io.Writer) error {
843         cmd := exec.Command("bash", "-")
844         if inst.EatMyData {
845                 cmd = exec.Command("eatmydata", "bash", "-")
846         }
847         cmd.Stdin = bytes.NewBufferString("set -ex -o pipefail\n" + script)
848         cmd.Stdout = stdout
849         cmd.Stderr = stderr
850         return cmd.Run()
851 }
852
853 func prodpkgs(osv osversion) []string {
854         pkgs := []string{
855                 "ca-certificates",
856                 "curl",
857                 "fuse",
858                 "git",
859                 "gitolite3",
860                 "graphviz",
861                 "haveged",
862                 "libcurl3-gnutls",
863                 "libxslt1.1",
864                 "nginx",
865                 "python3",
866                 "sudo",
867         }
868         if osv.Debian || osv.Ubuntu {
869                 if osv.Debian && osv.Major == 8 {
870                         pkgs = append(pkgs, "libgnutls-deb0-28") // sdk/cwl
871                 } else if osv.Debian && osv.Major >= 10 || osv.Ubuntu && osv.Major >= 16 {
872                         pkgs = append(pkgs, "python3-distutils") // sdk/cwl
873                 }
874                 return append(pkgs,
875                         "mime-support", // keep-web
876                 )
877         } else if osv.Centos {
878                 return append(pkgs,
879                         "fuse-libs", // services/fuse
880                         "mailcap",   // keep-web
881                 )
882         } else {
883                 panic("os version not supported")
884         }
885 }
886
887 func ProductionDependencies() ([]string, error) {
888         osv, err := identifyOS()
889         if err != nil {
890                 return nil, err
891         }
892         return prodpkgs(osv), nil
893 }