You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

集群中使用Singularity拉取镜像时遇到错误求助

问题场景

使用Singularity 3.7.2拉取CERN官方的cmsopendata/cmssw_7_6_7-slc6_amd64_gcc493 Docker镜像时,转换OCI blob到SIF格式阶段出现大量警告,最终抛出以下错误:

While making image from oci registry: error fetching image to cache: while building SIF from layers: packer failed to pack: while unpacking tmpfs: error unpacking rootfs: unpack layer: unpack entry: var/lib/yum/yumdb/m/d1e78f5adcafeb6c7d05cf71d17fb5196f487db5-mesa-libgbm-11.0.7-4.el6-x86_64/checksum_type: link: unpriv.link: unpriv.wrap target: too many links

执行的操作步骤为:

cd /scratch/$USER
mkdir -p singularity/{cache,temp}
mkdir my_containers
module load singularity/3.7.2
export SINGULARITY_CACHEDIR=/scratch/$USER/singularity/cache
export SINGULARITY_TMPDIR=/scratch/$USER/singularity/temp
cd my_containers
singularity pull ./cms7poet.sif docker://cmsopendata/cmssw_7_6_7-slc6_amd64_gcc493

已尝试chmod -R 777 [directory]但未解决问题。

解决方案

1. 升级Singularity版本

Singularity 3.7.x系列在无根模式下处理硬链接存在已知bug,升级到3.8.0及以上版本可修复该问题。若集群提供更高版本,执行以下命令切换:

module unload singularity/3.7.2
module load singularity/3.8.0  # 替换为集群可用的更高版本

切换完成后重新执行singularity pull命令即可。

2. 使用--fakeroot选项拉取

如果无法升级版本,可通过--fakeroot参数模拟root权限拉取,绕过无根模式下的硬链接数量限制:

singularity pull --fakeroot ./cms7poet.sif docker://cmsopendata/cmssw_7_6_7-slc6_amd64_gcc493

注意:部分集群可能需要管理员预先启用fakeroot权限,若执行失败可联系集群管理员确认。

3. 先拉取Docker镜像再转换为SIF

若上述方法均无效,可先通过Docker拉取镜像并导出为tar包,再用Singularity导入生成SIF文件:

# 1. 拉取Docker镜像(需集群节点安装Docker)
docker pull cmsopendata/cmssw_7_6_7-slc6_amd64_gcc493
# 2. 将镜像导出为tar归档文件
docker save cmsopendata/cmssw_7_6_7-slc6_amd64_gcc493 -o cms_image.tar
# 3. 用Singularity从tar包构建SIF镜像
singularity build ./cms7poet.sif docker-archive://cms_image.tar

4. 修正缓存与临时目录权限

虽然你已尝试过权限修改,但确保缓存和临时目录使用更安全的权限配置(仅当前用户可读写),避免潜在权限冲突:

chmod -R 700 /scratch/$USER/singularity/{cache,temp}

内容的提问来源于stack exchange,提问作者Newbie

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 09:10:05