-
Notifications
You must be signed in to change notification settings - Fork 190
[8.0] Interpret outputPath with LFN: prefix as an absolute one #8603
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: rel-v8r0
Are you sure you want to change the base?
Changes from all commits
0045bac
ad22da4
ab0fb97
e7fb85f
9e7827f
6db9106
12535c3
dadf667
279175f
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -70,11 +70,11 @@ In this section all the attributes that can be used in the DIRAC JDL job descrip | |
| +---------------------+---------------------------------------------+-------------------------------------------------------------------------------------+ | ||
| | *InputDataPolicy* | Job input data policy | InputDataPolicy = ``"DIRAC.WorkloadManagementSystem.Client.DownloadInputData";`` | | ||
| +---------------------+---------------------------------------------+-------------------------------------------------------------------------------------+ | ||
| | *OutputData* | Job output data files | OutputData = ``{"output1","output2"};`` | | ||
| | *OutputData* [1] | Job output data files | OutputData = ``{"output1","output2"};`` | | ||
| +---------------------+---------------------------------------------+-------------------------------------------------------------------------------------+ | ||
| | *OutputPath* | The output data path in the File Catalog | OutputPath = ``{"/myjobs/output"};`` | | ||
| | *OutputPath* [2] | The output data path in the File Catalog | OutputPath = ``{"/myjobs/output"};`` | | ||
| +---------------------+---------------------------------------------+-------------------------------------------------------------------------------------+ | ||
| | *OutputSE* | The output data Storage Element | OutputSE = ``{"DIRAC-USER"};`` | | ||
| | *OutputSE* [3] | The output data Storage Element | OutputSE = ``{"DIRAC-USER"};`` | | ||
| +---------------------+---------------------------------------------+-------------------------------------------------------------------------------------+ | ||
| | | | ||
| | :subtitle:`Parametric Jobs` | | ||
|
|
@@ -91,3 +91,26 @@ In this section all the attributes that can be used in the DIRAC JDL job descrip | |
| +---------------------+---------------------------------------------+-------------------------------------------------------------------------------------+ | ||
| | *ParameterFactor* | Parameter multiplier | ParameterFactor = 1.1; (default 1.) | | ||
| +---------------------+---------------------------------------------+-------------------------------------------------------------------------------------+ | ||
|
|
||
| 1. Elements of OutputData can be specified in several forms: | ||
|
|
||
| - filenames; in this case files with the specified names will be looked for in the job directory and uploaded | ||
| to a location specified by the OutputPath (see below); | ||
| - filenames with wild cards, e.g. ``"*.log"`` ; same after the filenames expansion; | ||
| - output data specified in a form ``"LFN:/vo/full/destination/path/filename"``; in this case the file ``"filename"`` | ||
| in the job directory will be uploaded to the specified LFN path without taking into account the OutputPath. | ||
| Note that "filename" here can be also specified with wild cards, e.g. ``"LFN:/vo/full/destination/path/*.log"`` . | ||
|
|
||
| 2. The OutputPath can be specified in several ways | ||
|
|
||
| - if not given, it will be taken as the user's home directory + the job directory | ||
| for example ``"/lhcb/user/a/atsareg/1234/1234567"``, where 1234567 is the job ID; | ||
| - if given as a path starting with "/", it will be appended to the user's home | ||
| directory, e.g. outputPath = ``"/my/analysis"`` will make output files to go to the | ||
| ``"/lhcb/user/a/atsareg/my/analysis"`` directory | ||
| - if given as ``"LFN:/output/path"``, it will be taken as an absolute path for | ||
| output files in the logical namespace. It is the responsibility of the user to make | ||
| sure that this path is accessible for writing for the user's data. | ||
|
|
||
| 3. If multiple output SEs are specified, they will be tried one-by-one for each | ||
| output file until a successful file upload. | ||
|
Comment on lines
+115
to
+116
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Please clarify this: does it mean that it will be uploaded (eventually) to all SEs, or it's "done" after the first upload? |
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -951,9 +951,19 @@ def __transferOutputDataFiles(self, outputData, outputSE, outputPath): | |
| else: | ||
| nonlfnList.append(out) | ||
|
|
||
| # Check whether list of outputData has a globbable pattern | ||
| # Check whether the list of LFNs has globbable patterns | ||
| globbedLfnList = [] | ||
| for lfn in lfnList: | ||
| lfnPath = os.path.dirname(lfn) | ||
| lfnLocal = os.path.basename(lfn) | ||
| globbedLfnList += [os.path.join(lfnPath, gLfn) for gLfn in List.uniqueElements(getGlobbedFiles(lfnLocal))] | ||
| if globbedLfnList and globbedLfnList != lfnList: | ||
| self.log.info("Found a pattern in the output data LFN list, LFNs to upload are:", ", ".join(globbedLfnList)) | ||
| lfnList = globbedLfnList | ||
|
|
||
| # Check whether the list of outputData has a globbable pattern | ||
|
Comment on lines
+954
to
+964
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. There is a code duplication between these inserted lines and those that follow, care to refactor for simplicity? |
||
| globbedOutputList = List.uniqueElements(getGlobbedFiles(nonlfnList)) | ||
| if globbedOutputList != nonlfnList and globbedOutputList: | ||
| if globbedOutputList and globbedOutputList != nonlfnList: | ||
| self.log.info( | ||
| "Found a pattern in the output data file list, files to upload are:", ", ".join(globbedOutputList) | ||
| ) | ||
|
|
@@ -1113,6 +1123,10 @@ def __getLFNfromOutputFile(self, outputFile, outputPath=""): | |
| # If output path is given, append it to the user path and put output files in this directory | ||
| if outputPath.startswith("/"): | ||
| outputPath = outputPath[1:] | ||
| # If output path is given with the LFN: prefix, take it as an absolute path | ||
| elif outputPath.startswith("LFN:"): | ||
| outputPath = outputPath[4:] | ||
| basePath = "" | ||
|
Comment on lines
+1126
to
+1129
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Shouldn't this block be before the previous 2 lines? For the case when |
||
| else: | ||
| # By default the output path is constructed from the job id | ||
| subdir = str(int(self.jobID / 1000)) | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I would like to double check this. What if the user is indeed "not prevented" to upload to such location, but there are no effective policies preventing it? For example, is a simple user prevented from specifying
"LFN:/lhcb/user/a/anotheruser"?Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What does prevent it now, if anything ? We've been getting around this restriction for ever by using dirac-dms-add-file directly.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I am not trying to fix the whole loose security system of the grid, because as we know "the tokens will solve that" ™️
But at least we can try to fix one such use case server side.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If you are feeling ambitious ;-). But I have never seen an incident like that.