如何以其他用户身份提交Slurm作业并防止访问其他用户文件
Hey there! Let's break down your issues step by step—first fixing the stuck jobs, then addressing those permission questions.
一、解决作业挂起(launch failed requeued held)的问题
Your first two attempts using sbatch --uid=1004 failed because Slurm typically restricts the --uid flag to administrative users by default. Regular users like main_user can't just swap UIDs when submitting jobs unless your cluster's Slurm config explicitly allows it.
The workaround you tried—sudo su - newuser ; sbatch run.sh—works perfectly because you're fully switching to the newuser identity first (the - ensures you load their full shell environment) before submitting the job. This aligns with Slurm's normal user permission model, so there's no conflict when launching the job.
Also, quick check: your initial user/account setup was spot-on:
sudo useradd -m newuser -d /home/newuser sacctmgr add account newuser --immediate sacctmgr create user newuser defaultaccount=newuser adminlevel=[None] --immediate
These steps correctly linked newuser to their own Slurm account, laying the right foundation for permission isolation.
二、chmod go-rwx /home/* 或 chmod 700 ~/* 是否能有效保护数据?
Short answer: Yes, both will block other users (including newuser) from accessing your sensitive files, but there are key details to note for each:
1. chmod go-rwx /home/*
This command locks down all user home directories in /home by removing read/write/execute permissions for group and other users. It's a great global protection measure:
- Other users won't even be able to list the contents of these home directories, let alone modify them
- Note: You'll need sudo privileges to run this, since you're modifying permissions on other users' directories
2. chmod 700 ~/*
This targets top-level files and folders in your main_user home directory, setting them to owner-only access. A couple of caveats here:
- It doesn't recursively modify permissions inside subfolders—if any subdirectories had open permissions before, their contents might still be accessible
- For a more robust lock on your own home directory, just modify the directory itself:
chmod 700 /home/main_user. This blocks other users from even entering your home folder, which is a stronger first line of defense - If you need to lock down every file/subfolder recursively, use
chmod -R 700 /home/main_user—but be careful! This will override any existing group/shared permissions, so only use it if you don't need to share files with others.
Final Takeaways
- Stick with
sudo su - newuserfollowed bysbatch run.shfor submitting jobs as the restricted user—it's the most reliable way to avoid Slurm's UID restrictions - Use
chmod go-rwx /home/*(with sudo) for global home directory protection, orchmod 700 /home/main_userto lock down just your own space—both will effectively block unauthorized access
内容的提问来源于stack exchange,提问作者alper

