Merge pull request #20400 from bernt-matthias/fix_20395

[25.0] Add job config variable for singularity `--contain`
This commit is contained in:
Martin Cech
2025-06-06 08:42:21 +02:00
committed by GitHub
3 changed files with 24 additions and 5 deletions
@@ -586,6 +586,24 @@ execution:
# argument by default. You can turn this off by setting singularity_cleanenv to `false`.
#singularity_cleanenv: true
# Singularity by default inherits the PID namespace, this can give
# issues with multiprocessing, hence galaxy passes the `--pid` argument
# by default to isolate the PID namespace. You can turn this off by setting
# singularity_pid to `false`.
#singularity_pid: true
# Singularity by default inherits the IPC namespace, this can give
# issues with multiprocessing, hence Galaxy passes the `--ipc` argument
# by default to isolate the IPC namespace. You can turn this off by setting
# singularity_ipc to `false`.
#singularity_ipc: true
# Singularity mounts some directories, such as $HOME and $PWD by default.
# Setting singularity_contain to `true` disables this behaviour and only allows explicitly
# requested volumes to be mounted. This gives full control over
# the mounting behavior.
#singularity_contain: true
# Pass extra arguments to the singularity exec command not covered by the
# above options.
#singularity_run_extra_arguments: ''
@@ -590,6 +590,7 @@ class SingularityContainer(Container, HasDockerLikeVolumes):
cleanenv=asbool(self.prop("cleanenv", singularity_util.DEFAULT_CLEANENV)),
ipc=asbool(self.prop("ipc", singularity_util.DEFAULT_IPC)),
pid=asbool(self.prop("pid", singularity_util.DEFAULT_PID)),
contain=asbool(self.prop("contain", singularity_util.DEFAULT_CONTAIN)),
no_mount=self.prop("no_mount", singularity_util.DEFAULT_NO_MOUNT),
**self.get_singularity_target_kwds(),
)
@@ -19,6 +19,7 @@ DEFAULT_SINGULARITY_COMMAND = "singularity"
DEFAULT_CLEANENV = True
DEFAULT_IPC = True
DEFAULT_PID = True
DEFAULT_CONTAIN = True
DEFAULT_NO_MOUNT = ["tmp"]
DEFAULT_SUDO = False
DEFAULT_SUDO_COMMAND = "sudo"
@@ -78,6 +79,7 @@ def build_singularity_run_command(
cleanenv: bool = DEFAULT_CLEANENV,
ipc: bool = DEFAULT_IPC,
pid: bool = DEFAULT_PID,
contain: bool = DEFAULT_CONTAIN,
no_mount: Optional[List[str]] = DEFAULT_NO_MOUNT,
) -> str:
volumes = volumes or []
@@ -96,11 +98,9 @@ def build_singularity_run_command(
)
command_parts.append("-s")
command_parts.append("exec")
# Singularity mounts some directories, such as $HOME and $PWD by default.
# using --contain disables this behaviour and only allows explicitly
# requested volumes to be mounted. This gives fully full-control over
# the mounting behavior.
command_parts.append("--contain")
if contain:
command_parts.append("--contain")
if working_directory:
command_parts.extend(["--pwd", shlex.quote(working_directory)])
if cleanenv: