85 lines · plain
1=================================2Documentation for /proc/sys/user/3=================================4 5kernel version 4.9.06 7Copyright (c) 2016 Eric Biederman <ebiederm@xmission.com>8 9------------------------------------------------------------------------------10 11This file contains the documentation for the sysctl files in12/proc/sys/user.13 14The files in this directory can be used to override the default15limits on the number of namespaces and other objects that have16per user per user namespace limits.17 18The primary purpose of these limits is to stop programs that19malfunction and attempt to create a ridiculous number of objects,20before the malfunction becomes a system wide problem. It is the21intention that the defaults of these limits are set high enough that22no program in normal operation should run into these limits.23 24The creation of per user per user namespace objects are charged to25the user in the user namespace who created the object and26verified to be below the per user limit in that user namespace.27 28The creation of objects is also charged to all of the users29who created user namespaces the creation of the object happens30in (user namespaces can be nested) and verified to be below the per user31limits in the user namespaces of those users.32 33This recursive counting of created objects ensures that creating a34user namespace does not allow a user to escape their current limits.35 36Currently, these files are in /proc/sys/user:37 38max_cgroup_namespaces39=====================40 41 The maximum number of cgroup namespaces that any user in the current42 user namespace may create.43 44max_ipc_namespaces45==================46 47 The maximum number of ipc namespaces that any user in the current48 user namespace may create.49 50max_mnt_namespaces51==================52 53 The maximum number of mount namespaces that any user in the current54 user namespace may create.55 56max_net_namespaces57==================58 59 The maximum number of network namespaces that any user in the60 current user namespace may create.61 62max_pid_namespaces63==================64 65 The maximum number of pid namespaces that any user in the current66 user namespace may create.67 68max_time_namespaces69===================70 71 The maximum number of time namespaces that any user in the current72 user namespace may create.73 74max_user_namespaces75===================76 77 The maximum number of user namespaces that any user in the current78 user namespace may create.79 80max_uts_namespaces81==================82 83 The maximum number of user namespaces that any user in the current84 user namespace may create.85