diff --git a/lib/galaxy/config/sample/job_conf.sample.yml b/lib/galaxy/config/sample/job_conf.sample.yml index 849aabba1ee..85b3d12c638 100644 --- a/lib/galaxy/config/sample/job_conf.sample.yml +++ b/lib/galaxy/config/sample/job_conf.sample.yml @@ -586,6 +586,24 @@ execution: # argument by default. You can turn this off by setting singularity_cleanenv to `false`. #singularity_cleanenv: true + # Singularity by default inherits the PID namespace, this can give + # issues with multiprocessing, hence galaxy passes the `--pid` argument + # by default to isolate the PID namespace. You can turn this off by setting + # singularity_pid to `false`. + #singularity_pid: true + + # Singularity by default inherits the IPC namespace, this can give + # issues with multiprocessing, hence Galaxy passes the `--ipc` argument + # by default to isolate the IPC namespace. You can turn this off by setting + # singularity_ipc to `false`. + #singularity_ipc: true + + # Singularity mounts some directories, such as $HOME and $PWD by default. + # Setting singularity_contain to `true` disables this behaviour and only allows explicitly + # requested volumes to be mounted. This gives full control over + # the mounting behavior. + #singularity_contain: true + # Pass extra arguments to the singularity exec command not covered by the # above options. #singularity_run_extra_arguments: '' diff --git a/lib/galaxy/tool_util/deps/container_classes.py b/lib/galaxy/tool_util/deps/container_classes.py index a2c05f0068b..723abb14933 100644 --- a/lib/galaxy/tool_util/deps/container_classes.py +++ b/lib/galaxy/tool_util/deps/container_classes.py @@ -590,6 +590,7 @@ class SingularityContainer(Container, HasDockerLikeVolumes): cleanenv=asbool(self.prop("cleanenv", singularity_util.DEFAULT_CLEANENV)), ipc=asbool(self.prop("ipc", singularity_util.DEFAULT_IPC)), pid=asbool(self.prop("pid", singularity_util.DEFAULT_PID)), + contain=asbool(self.prop("contain", singularity_util.DEFAULT_CONTAIN)), no_mount=self.prop("no_mount", singularity_util.DEFAULT_NO_MOUNT), **self.get_singularity_target_kwds(), ) diff --git a/lib/galaxy/tool_util/deps/singularity_util.py b/lib/galaxy/tool_util/deps/singularity_util.py index 081c706fc3c..77ee94a0365 100644 --- a/lib/galaxy/tool_util/deps/singularity_util.py +++ b/lib/galaxy/tool_util/deps/singularity_util.py @@ -19,6 +19,7 @@ DEFAULT_SINGULARITY_COMMAND = "singularity" DEFAULT_CLEANENV = True DEFAULT_IPC = True DEFAULT_PID = True +DEFAULT_CONTAIN = True DEFAULT_NO_MOUNT = ["tmp"] DEFAULT_SUDO = False DEFAULT_SUDO_COMMAND = "sudo" @@ -78,6 +79,7 @@ def build_singularity_run_command( cleanenv: bool = DEFAULT_CLEANENV, ipc: bool = DEFAULT_IPC, pid: bool = DEFAULT_PID, + contain: bool = DEFAULT_CONTAIN, no_mount: Optional[List[str]] = DEFAULT_NO_MOUNT, ) -> str: volumes = volumes or [] @@ -96,11 +98,9 @@ def build_singularity_run_command( ) command_parts.append("-s") command_parts.append("exec") - # Singularity mounts some directories, such as $HOME and $PWD by default. - # using --contain disables this behaviour and only allows explicitly - # requested volumes to be mounted. This gives fully full-control over - # the mounting behavior. - command_parts.append("--contain") + + if contain: + command_parts.append("--contain") if working_directory: command_parts.extend(["--pwd", shlex.quote(working_directory)]) if cleanenv: