You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何以其他用户身份提交Slurm作业并防止访问其他用户文件

Slurm作业权限隔离与提交问题解决方案

Hey there! Let's break down your issues step by step—first fixing the stuck jobs, then addressing those permission questions.

一、解决作业挂起(launch failed requeued held)的问题

Your first two attempts using sbatch --uid=1004 failed because Slurm typically restricts the --uid flag to administrative users by default. Regular users like main_user can't just swap UIDs when submitting jobs unless your cluster's Slurm config explicitly allows it.

The workaround you tried—sudo su - newuser ; sbatch run.sh—works perfectly because you're fully switching to the newuser identity first (the - ensures you load their full shell environment) before submitting the job. This aligns with Slurm's normal user permission model, so there's no conflict when launching the job.

Also, quick check: your initial user/account setup was spot-on:

sudo useradd -m newuser -d /home/newuser
sacctmgr add account newuser --immediate
sacctmgr create user newuser defaultaccount=newuser adminlevel=[None] --immediate

These steps correctly linked newuser to their own Slurm account, laying the right foundation for permission isolation.

二、chmod go-rwx /home/* 或 chmod 700 ~/* 是否能有效保护数据?

Short answer: Yes, both will block other users (including newuser) from accessing your sensitive files, but there are key details to note for each:

1. chmod go-rwx /home/*

This command locks down all user home directories in /home by removing read/write/execute permissions for group and other users. It's a great global protection measure:

  • Other users won't even be able to list the contents of these home directories, let alone modify them
  • Note: You'll need sudo privileges to run this, since you're modifying permissions on other users' directories

2. chmod 700 ~/*

This targets top-level files and folders in your main_user home directory, setting them to owner-only access. A couple of caveats here:

  • It doesn't recursively modify permissions inside subfolders—if any subdirectories had open permissions before, their contents might still be accessible
  • For a more robust lock on your own home directory, just modify the directory itself: chmod 700 /home/main_user. This blocks other users from even entering your home folder, which is a stronger first line of defense
  • If you need to lock down every file/subfolder recursively, use chmod -R 700 /home/main_user—but be careful! This will override any existing group/shared permissions, so only use it if you don't need to share files with others.

Final Takeaways

  • Stick with sudo su - newuser followed by sbatch run.sh for submitting jobs as the restricted user—it's the most reliable way to avoid Slurm's UID restrictions
  • Use chmod go-rwx /home/* (with sudo) for global home directory protection, or chmod 700 /home/main_user to lock down just your own space—both will effectively block unauthorized access

内容的提问来源于stack exchange,提问作者alper

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:54:01