From 964a62bb2c971b659f82512417b74c81c5f1f755 Mon Sep 17 00:00:00 2001 From: Matthias Bernt Date: Wed, 4 Jun 2025 18:45:27 +0200 Subject: [PATCH 1/4] add job config for singularity --contain also move doc to yaml config job config file --- lib/galaxy/config/sample/job_conf.sample.yml | 13 +++++++++++++ lib/galaxy/tool_util/deps/container_classes.py | 1 + lib/galaxy/tool_util/deps/singularity_util.py | 10 +++++----- 3 files changed, 19 insertions(+), 5 deletions(-) diff --git a/lib/galaxy/config/sample/job_conf.sample.yml b/lib/galaxy/config/sample/job_conf.sample.yml index 849aabba1ee..28c47797c0a 100644 --- a/lib/galaxy/config/sample/job_conf.sample.yml +++ b/lib/galaxy/config/sample/job_conf.sample.yml @@ -586,6 +586,19 @@ execution: # argument by default. You can turn this off by setting singularity_cleanenv to `false`. #singularity_cleanenv: true + # Singularity by default inherits the IPC namespace, this can give + # issues with multiprocessing, hence galaxy passes the `ipc` argument + # by default to isolate the PID namespace. You can turn this of by setting + # singularity_ipc to `false`. + #singularity_pid: true + #singularity_ipc: true + + # Singularity mounts some directories, such as $HOME and $PWD by default. + # using --contain disables this behaviour and only allows explicitly + # requested volumes to be mounted. This gives fully full-control over + # the mounting behavior. + #singulartity_contains: true + # Pass extra arguments to the singularity exec command not covered by the # above options. #singularity_run_extra_arguments: '' diff --git a/lib/galaxy/tool_util/deps/container_classes.py b/lib/galaxy/tool_util/deps/container_classes.py index a2c05f0068b..723abb14933 100644 --- a/lib/galaxy/tool_util/deps/container_classes.py +++ b/lib/galaxy/tool_util/deps/container_classes.py @@ -590,6 +590,7 @@ class SingularityContainer(Container, HasDockerLikeVolumes): cleanenv=asbool(self.prop("cleanenv", singularity_util.DEFAULT_CLEANENV)), ipc=asbool(self.prop("ipc", singularity_util.DEFAULT_IPC)), pid=asbool(self.prop("pid", singularity_util.DEFAULT_PID)), + contain=asbool(self.prop("contain", singularity_util.DEFAULT_CONTAIN)), no_mount=self.prop("no_mount", singularity_util.DEFAULT_NO_MOUNT), **self.get_singularity_target_kwds(), ) diff --git a/lib/galaxy/tool_util/deps/singularity_util.py b/lib/galaxy/tool_util/deps/singularity_util.py index 081c706fc3c..77ee94a0365 100644 --- a/lib/galaxy/tool_util/deps/singularity_util.py +++ b/lib/galaxy/tool_util/deps/singularity_util.py @@ -19,6 +19,7 @@ DEFAULT_SINGULARITY_COMMAND = "singularity" DEFAULT_CLEANENV = True DEFAULT_IPC = True DEFAULT_PID = True +DEFAULT_CONTAIN = True DEFAULT_NO_MOUNT = ["tmp"] DEFAULT_SUDO = False DEFAULT_SUDO_COMMAND = "sudo" @@ -78,6 +79,7 @@ def build_singularity_run_command( cleanenv: bool = DEFAULT_CLEANENV, ipc: bool = DEFAULT_IPC, pid: bool = DEFAULT_PID, + contain: bool = DEFAULT_CONTAIN, no_mount: Optional[List[str]] = DEFAULT_NO_MOUNT, ) -> str: volumes = volumes or [] @@ -96,11 +98,9 @@ def build_singularity_run_command( ) command_parts.append("-s") command_parts.append("exec") - # Singularity mounts some directories, such as $HOME and $PWD by default. - # using --contain disables this behaviour and only allows explicitly - # requested volumes to be mounted. This gives fully full-control over - # the mounting behavior. - command_parts.append("--contain") + + if contain: + command_parts.append("--contain") if working_directory: command_parts.extend(["--pwd", shlex.quote(working_directory)]) if cleanenv: From a71d4dd0dbc3083358466ebee91fedbce149cf87 Mon Sep 17 00:00:00 2001 From: M Bernt Date: Wed, 4 Jun 2025 21:03:38 +0200 Subject: [PATCH 2/4] Fix sample config Co-authored-by: Nate Coraor --- lib/galaxy/config/sample/job_conf.sample.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/galaxy/config/sample/job_conf.sample.yml b/lib/galaxy/config/sample/job_conf.sample.yml index 28c47797c0a..6f4dba5f7d0 100644 --- a/lib/galaxy/config/sample/job_conf.sample.yml +++ b/lib/galaxy/config/sample/job_conf.sample.yml @@ -597,7 +597,7 @@ execution: # using --contain disables this behaviour and only allows explicitly # requested volumes to be mounted. This gives fully full-control over # the mounting behavior. - #singulartity_contains: true + #singulartity_contain: true # Pass extra arguments to the singularity exec command not covered by the # above options. From 704f0620f517636f99530fa74a1d5fc75e17941d Mon Sep 17 00:00:00 2001 From: M Bernt Date: Thu, 5 Jun 2025 09:31:28 +0200 Subject: [PATCH 3/4] Doc improvements Co-authored-by: Nicola Soranzo --- lib/galaxy/config/sample/job_conf.sample.yml | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/lib/galaxy/config/sample/job_conf.sample.yml b/lib/galaxy/config/sample/job_conf.sample.yml index 6f4dba5f7d0..2a9a33fd0ef 100644 --- a/lib/galaxy/config/sample/job_conf.sample.yml +++ b/lib/galaxy/config/sample/job_conf.sample.yml @@ -586,18 +586,22 @@ execution: # argument by default. You can turn this off by setting singularity_cleanenv to `false`. #singularity_cleanenv: true - # Singularity by default inherits the IPC namespace, this can give - # issues with multiprocessing, hence galaxy passes the `ipc` argument - # by default to isolate the PID namespace. You can turn this of by setting - # singularity_ipc to `false`. + # Singularity by default inherits the PID namespace, this can give + # issues with multiprocessing, hence galaxy passes the `--pid` argument + # by default to isolate the PID namespace. You can turn this off by setting + # singularity_pid to `false`. #singularity_pid: true + Singularity by default inherits the IPC namespace, this can give + issues with multiprocessing, hence Galaxy passes the `--ipc` argument + by default to isolate the IPC namespace. You can turn this off by setting + singularity_ipc to `false`. #singularity_ipc: true # Singularity mounts some directories, such as $HOME and $PWD by default. - # using --contain disables this behaviour and only allows explicitly - # requested volumes to be mounted. This gives fully full-control over + # Setting singularity_contain to `true` disables this behaviour and only allows explicitly + # requested volumes to be mounted. This gives full control over # the mounting behavior. - #singulartity_contain: true + #singularity_contain: true # Pass extra arguments to the singularity exec command not covered by the # above options. From 0ed6442318304e8a3401899478ac84cdb34cfdd7 Mon Sep 17 00:00:00 2001 From: M Bernt Date: Thu, 5 Jun 2025 09:33:11 +0200 Subject: [PATCH 4/4] Add missing comments --- lib/galaxy/config/sample/job_conf.sample.yml | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/lib/galaxy/config/sample/job_conf.sample.yml b/lib/galaxy/config/sample/job_conf.sample.yml index 2a9a33fd0ef..85b3d12c638 100644 --- a/lib/galaxy/config/sample/job_conf.sample.yml +++ b/lib/galaxy/config/sample/job_conf.sample.yml @@ -591,10 +591,11 @@ execution: # by default to isolate the PID namespace. You can turn this off by setting # singularity_pid to `false`. #singularity_pid: true - Singularity by default inherits the IPC namespace, this can give - issues with multiprocessing, hence Galaxy passes the `--ipc` argument - by default to isolate the IPC namespace. You can turn this off by setting - singularity_ipc to `false`. + + # Singularity by default inherits the IPC namespace, this can give + # issues with multiprocessing, hence Galaxy passes the `--ipc` argument + # by default to isolate the IPC namespace. You can turn this off by setting + # singularity_ipc to `false`. #singularity_ipc: true # Singularity mounts some directories, such as $HOME and $PWD by default.