From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932305AbcHOUKd (ORCPT ); Mon, 15 Aug 2016 16:10:33 -0400 Received: from mail-pf0-f195.google.com ([209.85.192.195]:34265 "EHLO mail-pf0-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932207AbcHOUKa (ORCPT ); Mon, 15 Aug 2016 16:10:30 -0400 From: Andrei Vagin To: "Eric W. Biederman" Cc: containers@lists.linux-foundation.org, linux-kernel@vger.kernel.org, Andrei Vagin , Serge Hallyn , Kees Cook , Kirill Kolyshkin Subject: [PATCH 2/2] Documentation: describe /proc//userns_counts Date: Mon, 15 Aug 2016 13:10:22 -0700 Message-Id: <1471291822-539-3-git-send-email-avagin@openvz.org> X-Mailer: git-send-email 2.5.5 In-Reply-To: <1471291822-539-1-git-send-email-avagin@openvz.org> References: <1471291822-539-1-git-send-email-avagin@openvz.org> Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Kirill Kolyshkin This file provides current usage of user namespace counters. Signed-off-by: Kirill Kolyshkin Signed-off-by: Andrei Vagin --- Documentation/filesystems/proc.txt | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) diff --git a/Documentation/filesystems/proc.txt b/Documentation/filesystems/proc.txt index 68080ad..7300d9c 100644 --- a/Documentation/filesystems/proc.txt +++ b/Documentation/filesystems/proc.txt @@ -44,6 +44,7 @@ Table of Contents 3.8 /proc//fdinfo/ - Information about opened file 3.9 /proc//map_files - Information about memory mapped files 3.10 /proc//timerslack_ns - Task timerslack value + 3.11 /proc//userns_counts - User namespace counters 4 Configuring procfs 4.1 Mount options @@ -1889,6 +1890,35 @@ Valid values are from 0 - ULLONG_MAX An application setting the value must have PTRACE_MODE_ATTACH_FSCREDS level permissions on the task specified to change its timerslack_ns value. +3.11 /proc//userns_counts - User namespace counters +--------------------------------------------------------- + +This file provides current usage of user namespace counters. + +User namespace counters is a feature that allows to limit the number of various +kernel objects a user can create. These limits are set via /proc/sys/user/ +sysctls on a per user namespace basis and are applicable to all users in that +namespace. Therefore, the limits are the same for every user in a user +namespace. + +Each user has their own set of user namespace counters. Once a user creates a +new user namespace, every new object created inside that namespace is also +charged to the user. That means that a user is limited by their user namespace +limits, as well as the limits in their parent user namespaces. + + > cat /proc/813/userns_counts + user_namespaces 101000 1 + pid_namespaces 101000 1 + ipc_namespaces 101000 4 + net_namespaces 101000 2 + mnt_namespaces 101000 5 + mnt_namespaces 100000 1 + +The meanings of the columns are as follows, from left to right: + + Name Object name + UID User ID + Usage Current usage ------------------------------------------------------------------------------ Configuring procfs -- 2.5.5