On 2021-10-31 11:31 AM, JEAN-YVES SGRO via HTCondor-users wrote: ...
Is this something that makes sense?
Hopefully someone on condor team has something better to offer; I always subscribed to "life's too short to enable selinux" view and had "set `selinux=disabled`" as step #2 in our new system setup checklist.
I don't know how condor deals with singularity bind mounts, vanilla singularity container will by default mount /tmp which _may_ have a less restrictive selinux context host-side. I.e. you could try running in singularity, rather than docker, container and see if that works.
Dima