You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CircleCI中使用Singularity时根文件系统提取失败问题求助

问题

我创建了一个测试仓库用于测试Snakemake工作流的容器化,该工作流在本地和Slurm集群上均可正常运行,但在CircleCI中执行时持续报错,核心错误为:

FATAL:   while extracting /home/circleci/project/.snakemake/singularity/4f64024d9840ccf1a4d8836c5edc6aa5.simg: root filesystem extraction failed: extract command failed: ERROR  : Failed to set mount propagation: Operation not permitted

完整报错日志如下:

Building DAG of jobs...
Pulling singularity image docker://*********/test-containerize:0.0.0.
Using shell: /usr/bin/bash
Provided cores: 1 (use --cores to define parallelism)
Rules claiming more threads will be scaled down.
Conda environments: ignored
Job stats:
job         count    min threads    max threads
--------  -------  -------------  -------------
all             1              1              1
all_TEST        1              1              1
total           2              1              1

Select jobs to execute...

[Mon Dec 19 19:42:03 2022]
rule all_TEST:
    input: test.txt
    output: output.txt
    jobid: 1
    reason: Missing output files: output.txt
    resources: tmpdir=/tmp

Activating singularity image /home/circleci/project/.snakemake/singularity/4f64024d9840ccf1a4d8836c5edc6aa5.simg
INFO:    Converting SIF file to temporary sandbox...
FATAL:   while extracting /home/circleci/project/.snakemake/singularity/4f64024d9840ccf1a4d8836c5edc6aa5.simg: root filesystem extraction failed: extract command failed: ERROR  : Failed to set mount propagation: Operation not permitted
: exit status 1
[Mon Dec 19 19:42:03 2022]
Error in rule all_TEST:
    jobid: 1
    input: test.txt
    output: output.txt
    conda-env: /home/circleci/project/.snakemake/conda/cc6395ec670d10af0374c53e5653fb76_
    shell:
        cat test.txt > output.txt
        (one of the commands exited with non-zero exit code; note that snakemake uses bash strict mode!)

Shutting down, this might take some time.
Exiting because a job execution failed. Look above for error message
Complete log: .snakemake/log/2022-12-19T194136.569293.snakemake.log

Exited with code exit status 1

我推测是权限问题,但本地更复杂的工作流容器化时也出现相同错误,求解决办法。

解决方案

这个错误的核心原因是CircleCI执行环境默认没有足够权限,导致Singularity无法完成挂载传播设置。以下是几种可行的解决方法:

1. 跳过Singularity临时沙箱转换

Snakemake默认会将Singularity镜像转为临时沙箱运行,这一步需要特殊权限。可以通过添加参数直接使用SIF镜像运行:

snakemake --use-singularity --singularity-args "--no-sandbox"

2. 开启CircleCI job的特权模式

在CircleCI的config.yml中,给运行Snakemake的job开启特权模式,让Singularity获得所需权限:

jobs:
  run-snakemake:
    machine:
      image: ubuntu-2004:202201-02
    steps:
      - checkout
      - run:
          command: |
            sudo apt-get update && sudo apt-get install -y singularity-container
            pip install snakemake
          privileged: true
      - run:
          command: snakemake --use-singularity
          privileged: true

注意:特权模式会赋予job更高权限,请确保你的工作流和镜像来源可信。

3. 调整Singularity容器隔离参数

尝试添加--contain或--cleanenv参数,降低容器隔离级别以规避挂载传播需求:

snakemake --use-singularity --singularity-args "--contain --cleanenv"

4. 升级Singularity版本

CircleCI默认的Singularity版本可能较旧,新版本对权限处理更友好。可以在安装步骤中指定最新稳定版:

sudo wget -O- https://raw.githubusercontent.com/sylabs/singularity/main/install.sh | sudo sh -s -- --version 3.11.4

内容的提问来源于stack exchange,提问作者Ulthran

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 15:10:39