# Singularity error in downloaded pipeline

**URL:** <https://community.seqera.io/t/singularity-error-in-downloaded-pipeline/2267>\
**Category:** Ask for help\
**Tags:** nf-core, singularity, seqera-containers\
**Created:** [July 7, 2025, 10:31am UTC](https://community.seqera.io/t/singularity-error-in-downloaded-pipeline/2267 "2025-07-07T10:31:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![itrujnara](https://dub1.discourse-cdn.com/flex013/user_avatar/community.seqera.io/itrujnara/32/1897_2.png) [@itrujnara](https://community.seqera.io/u/itrujnara)\
**Post date:** [July 7, 2025, 10:31am UTC](https://community.seqera.io/t/singularity-error-in-downloaded-pipeline/2267/1 "2025-07-07T10:31:56Z")

</div>

I’m working on an nf-core pipeline, with the default CI set up. All release tests pass without issues, except one: pipeline download. The downloaded pipeline fails to run due to a Singularity issue. I get the following error:

```auto
 Command error:
  INFO: Converting SIF file to temporary sandbox...
  FATAL: while extracting /home/runner/work/reportho/reportho/./community-cr-prod.seqera.io-docker-registry-v2-blobs-sha256-6b-6b2900901bc81cfb5d255a250ee196f4e2f8707ba6de704178eb40151fd849f8-data.img: root filesystem extraction failed: extract command failed: ERROR : Failed to create container process: Operation not permitted
  : exit status 1

```

I’ve found information about this issue, but it was universally related to malformed containers. In this case, I am using a Seqera container, so no problems should arise. Has anyone experienced this issue, or do you have ideas on how to resolve it? The CI run can be found [here](https://github.com/nf-core/reportho/actions/runs/16047722045/job/45282920060?pr=89).

---

<div class="post-metadata">

**Author:** ![fmalmeida](https://dub1.discourse-cdn.com/flex013/user_avatar/community.seqera.io/fmalmeida/32/312_2.png) [@fmalmeida](https://community.seqera.io/u/fmalmeida)\
**Post date:** [July 10, 2025, 7:55am UTC](https://community.seqera.io/t/singularity-error-in-downloaded-pipeline/2267/2 "2025-07-10T07:55:36Z")

</div>

Hi @itrujnara ,

Checking your PR&branch, I believe it indeed is the case that the container might be incorrect.

In your `dev` branch, you have the following line for your “singularity” container:

```auto
https://community-cr-prod.seqera.io/docker/registry/v2/blobs/sha256/6b/6b2900901bc81cfb5d255a250ee196f4e2f8707ba6de704178eb40151fd849f8/data

```

This however, does not look like a proper singularity container, but rather a blob from docker.

In `seqera containers` you can, and should, create true singularity images that will look different from the one you have, they will be named like this, for example:

```auto
oras://community.wave.seqera.io/library/bcftools:1.2--6d4bdbc4b21ae250

```

So, I would recommend before trying to debug more, to just building a true singularity image in the `seqera containers` service, and using that to see if it resolves. If not, then we can try to debug more.

Example:

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/seqera/original/2X/3/3f167c4e8d6e2a94b81603ff4245e1b2bb7e3593.png)

---

<div class="post-metadata">

**Author:** ![ewels](https://dub1.discourse-cdn.com/flex013/user_avatar/community.seqera.io/ewels/32/1_2.png) [@ewels](https://community.seqera.io/u/ewels)\
**Post date:** [July 10, 2025, 10:47pm UTC](https://community.seqera.io/t/singularity-error-in-downloaded-pipeline/2267/3 "2025-07-10T22:47:09Z")

</div>

> This however, does not look like a proper singularity container, but rather a blob from docker.

I’m not sure that this is quite right @fmalmeida - both URLs are valid for Singularity containers from Seqera Containers. They just use different protocols: the first is `https` and the second is `oras`. Both should work with `singularity pull`. See [this blog post](https://nf-co.re/blog/2024/seqera-containers-part-2#singularity-oras-or-https) for a bit more description. For Seqera Containers, the `.sif` flat image _is_ a blob from the OCI registry. Singularity images just have a single layer with the one binary in it. Whether `https` or `oras` is better depends a little on use case, but for nf-core we recommend `https` (the first link) for reasons described in the blog post I linked above.

On the Seqera Containers web interface, you can choose `https` instead of `oras` with this check box:

 ![CleanShot 2025-07-10 at 23.41.44@2x](https://europe1.discourse-cdn.com/flex013/uploads/seqera/original/2X/1/15e9f48a6d3583c6e1c93e6ced15606c93a70c59.png)

That gives this URL:

```auto
https://community-cr-prod.seqera.io/docker/registry/v2/blobs/sha256/4e/4eb863d427b6e327abab4be2112d17760f86947eeaf3a214e1450bc680f14a49/data

```

Regarding what has gone wrong here, a search on Slack finds a [fairly recent thread](https://nfcore.slack.com/archives/CE6SDBX2A/p1739798359183649) where the same error was being discussed. In that case, the problem was that the GitHub Actions runner was running out of space whilst pulling the Singularity image. It’d be my guess that this is the root cause here as well.

---

<div class="post-metadata">

**Author:** ![fmalmeida](https://dub1.discourse-cdn.com/flex013/user_avatar/community.seqera.io/fmalmeida/32/312_2.png) [@fmalmeida](https://community.seqera.io/u/fmalmeida)\
**Post date:** [July 11, 2025, 5:28am UTC](https://community.seqera.io/t/singularity-error-in-downloaded-pipeline/2267/4 "2025-07-11T05:28:39Z")

</div>

Hi @ewels ,

Thanks for clarifying!! I was not aware it could look like that when https.

Sorry for that! And good to now know!

---

<div class="post-metadata">

**Author:** ![mahesh.binzerpanchal](https://dub1.discourse-cdn.com/flex013/user_avatar/community.seqera.io/mahesh.binzerpanchal/32/253_2.png) [@mahesh.binzerpanchal](https://community.seqera.io/u/mahesh.binzerpanchal)\
**Post date:** [July 11, 2025, 7:06am UTC](https://community.seqera.io/t/singularity-error-in-downloaded-pipeline/2267/5 "2025-07-11T07:06:29Z")

</div>

Could it be a disk space issue? How big is the image and how much space do the runners have to sandbox the image files?

---

<div class="post-metadata">

**Author:** ![Muneeb](https://dub1.discourse-cdn.com/flex013/user_avatar/community.seqera.io/muneeb/32/1181_2.png) [@Muneeb](https://community.seqera.io/u/Muneeb)\
**Post date:** [September 27, 2025, 8:56am UTC](https://community.seqera.io/t/singularity-error-in-downloaded-pipeline/2267/6 "2025-09-27T08:56:29Z")

</div>

I’ve encountered a similar issue on my local machine, especially when the container size was large. In those cases, pulling the container took too long and eventually triggered the error.

My workaround was to manually download the Docker image and convert it to SIF format — though this approach is quite complex and I wouldn’t recommend it unless necessary.

For your specific case on GitHub Actions runners, I strongly suspect the problem might be related to limited disk space on the runners. In many cases, simply rerunning the workflow resolves the issue.
