diff --git a/src/DIRAC/Resources/Computing/SingularityComputingElement.py b/src/DIRAC/Resources/Computing/SingularityComputingElement.py index 6cddeb68900..83e783e3195 100644 --- a/src/DIRAC/Resources/Computing/SingularityComputingElement.py +++ b/src/DIRAC/Resources/Computing/SingularityComputingElement.py @@ -14,6 +14,7 @@ import io import json import os +import re import shutil import sys import tempfile @@ -85,6 +86,18 @@ """ +ENV_VAR_WHITELIST = [ + r"TERM", + r"VOMS_.*", + r"X509_.*", + r"XRD_.*", + r"Xrd.*", + r"DIRAC.*", # will take also DIRAC and DIRACOS + r"BEARER_TOKEN.*", +] +ENV_VAR_WHITELIST = re.compile(r"^(" + r"|".join(ENV_VAR_WHITELIST) + r")$") + + class SingularityComputingElement(ComputingElement): """A Computing Element for running a job within a Singularity container.""" @@ -311,9 +324,8 @@ def __getEnv(self): """Gets the environment for use within the container. We blank almost everything to prevent contamination from the host system. """ - payloadEnv = {} - if "TERM" in os.environ: - payloadEnv["TERM"] = os.environ["TERM"] + + payloadEnv = {k: v for k, v in os.environ.items() if ENV_VAR_WHITELIST.match(k)} payloadEnv["TMP"] = "/tmp" payloadEnv["TMPDIR"] = "/tmp" payloadEnv["X509_USER_PROXY"] = os.path.join(self.__innerdir, "proxy")