1 ================================= 1 ================================= 2 Documentation for /proc/sys/user/ 2 Documentation for /proc/sys/user/ 3 ================================= 3 ================================= 4 4 5 kernel version 4.9.0 5 kernel version 4.9.0 6 6 7 Copyright (c) 2016 Eric Biederman< 7 Copyright (c) 2016 Eric Biederman <ebiederm@xmission.com> 8 8 9 ---------------------------------------------- 9 ------------------------------------------------------------------------------ 10 10 11 This file contains the documentation for the s 11 This file contains the documentation for the sysctl files in 12 /proc/sys/user. 12 /proc/sys/user. 13 13 14 The files in this directory can be used to ove 14 The files in this directory can be used to override the default 15 limits on the number of namespaces and other o 15 limits on the number of namespaces and other objects that have 16 per user per user namespace limits. 16 per user per user namespace limits. 17 17 18 The primary purpose of these limits is to stop 18 The primary purpose of these limits is to stop programs that 19 malfunction and attempt to create a ridiculous 19 malfunction and attempt to create a ridiculous number of objects, 20 before the malfunction becomes a system wide p 20 before the malfunction becomes a system wide problem. It is the 21 intention that the defaults of these limits ar 21 intention that the defaults of these limits are set high enough that 22 no program in normal operation should run into 22 no program in normal operation should run into these limits. 23 23 24 The creation of per user per user namespace ob 24 The creation of per user per user namespace objects are charged to 25 the user in the user namespace who created the 25 the user in the user namespace who created the object and 26 verified to be below the per user limit in tha 26 verified to be below the per user limit in that user namespace. 27 27 28 The creation of objects is also charged to all 28 The creation of objects is also charged to all of the users 29 who created user namespaces the creation of th 29 who created user namespaces the creation of the object happens 30 in (user namespaces can be nested) and verifie 30 in (user namespaces can be nested) and verified to be below the per user 31 limits in the user namespaces of those users. 31 limits in the user namespaces of those users. 32 32 33 This recursive counting of created objects ens 33 This recursive counting of created objects ensures that creating a 34 user namespace does not allow a user to escape 34 user namespace does not allow a user to escape their current limits. 35 35 36 Currently, these files are in /proc/sys/user: 36 Currently, these files are in /proc/sys/user: 37 37 38 max_cgroup_namespaces 38 max_cgroup_namespaces 39 ===================== 39 ===================== 40 40 41 The maximum number of cgroup namespaces that 41 The maximum number of cgroup namespaces that any user in the current 42 user namespace may create. 42 user namespace may create. 43 43 44 max_ipc_namespaces 44 max_ipc_namespaces 45 ================== 45 ================== 46 46 47 The maximum number of ipc namespaces that an 47 The maximum number of ipc namespaces that any user in the current 48 user namespace may create. 48 user namespace may create. 49 49 50 max_mnt_namespaces 50 max_mnt_namespaces 51 ================== 51 ================== 52 52 53 The maximum number of mount namespaces that 53 The maximum number of mount namespaces that any user in the current 54 user namespace may create. 54 user namespace may create. 55 55 56 max_net_namespaces 56 max_net_namespaces 57 ================== 57 ================== 58 58 59 The maximum number of network namespaces tha 59 The maximum number of network namespaces that any user in the 60 current user namespace may create. 60 current user namespace may create. 61 61 62 max_pid_namespaces 62 max_pid_namespaces 63 ================== 63 ================== 64 64 65 The maximum number of pid namespaces that an 65 The maximum number of pid namespaces that any user in the current 66 user namespace may create. 66 user namespace may create. 67 67 68 max_time_namespaces 68 max_time_namespaces 69 =================== 69 =================== 70 70 71 The maximum number of time namespaces that a 71 The maximum number of time namespaces that any user in the current 72 user namespace may create. 72 user namespace may create. 73 73 74 max_user_namespaces 74 max_user_namespaces 75 =================== 75 =================== 76 76 77 The maximum number of user namespaces that a 77 The maximum number of user namespaces that any user in the current 78 user namespace may create. 78 user namespace may create. 79 79 80 max_uts_namespaces 80 max_uts_namespaces 81 ================== 81 ================== 82 82 83 The maximum number of user namespaces that a 83 The maximum number of user namespaces that any user in the current 84 user namespace may create. 84 user namespace may create.
Linux® is a registered trademark of Linus Torvalds in the United States and other countries.
TOMOYO® is a registered trademark of NTT DATA CORPORATION.