Discussion:
setting limits for users - ulimit: open files: cannot modify limit: Operation not permitted
(too old to reply)
zedkay
2011-10-27 14:24:57 UTC
Permalink
Hi there,

I am trying to set unlimited nprocs and open files for all users on a
server. I have set this:


fingerprint-auth: session required pam_limits.so
fingerprint-auth-ac: session required pam_limits.so
password-auth: session required pam_limits.so
password-auth-ac: session required pam_limits.so
runuser:session required pam_limits.so
smartcard-auth: session required pam_limits.so
smartcard-auth-ac: session required pam_limits.so
su: session required pam_limits.so debug
sudo: session required pam_limits.so
sudo-i: session required pam_limits.so
system-auth: session required pam_limits.so debug
system-auth-ac: session required pam_limits.so debug

/etc/security/limits.conf:
* soft nofiles unlimited
* hard nofiles unlimited
* hard nproc unlimited
* soft nproc unlimited

/etc/security/limits.d/90-nproc.conf
* soft nproc unlimit

However, users are unable to set anything useful:


# su - tomcat
-bash-4.1$ ulimit -n 2048
-bash: ulimit: open files: cannot modify limit: Operation not permitted
-bash-4.1$ ulimit -a
core file size (blocks, -c) 0
data seg size (kbytes, -d) unlimited
scheduling priority (-e) 0
file size (blocks, -f) unlimited
pending signals (-i) 95197
max locked memory (kbytes, -l) 64
max memory size (kbytes, -m) unlimited
open files (-n) 1024
pipe size (512 bytes, -p) 8
POSIX message queues (bytes, -q) 819200
real-time priority (-r) 0
stack size (kbytes, -s) 10240
cpu time (seconds, -t) unlimited
max user processes (-u) unlimited
virtual memory (kbytes, -v) unlimited
file locks (-x) unlimited

AS a result their compilations all bomb out.

# cat /etc/redhat-release
Red Hat Enterprise Linux Server release 6.0 (Santiago

I've googles for hours, and so far nothing has worked. There ought to be
a simple method to allow this. Does anyone know what it is?

Best regards, z
--
Please do not reply to my Email address. It is a faux Email address.
Cyberpunk FPS/MMORG www.neocron.com
Runs on Windows, platinum in latest WINE/Ubuntu. Running since 2002.
Johnny Rebel
2011-10-28 23:23:51 UTC
Permalink
Post by zedkay
Hi there,
I am trying to set unlimited nprocs and open files for all users on a
fingerprint-auth: session required pam_limits.so
fingerprint-auth-ac: session required pam_limits.so
password-auth: session required pam_limits.so
password-auth-ac: session required pam_limits.so
runuser:session required pam_limits.so
smartcard-auth: session required pam_limits.so
smartcard-auth-ac: session required pam_limits.so
su: session required pam_limits.so debug
sudo: session required pam_limits.so
sudo-i: session required pam_limits.so
system-auth: session required pam_limits.so debug
system-auth-ac: session required pam_limits.so debug
* soft nofiles unlimited
* hard nofiles unlimited
* hard nproc unlimited
* soft nproc unlimited
/etc/security/limits.d/90-nproc.conf
* soft nproc unlimit
# su - tomcat
-bash-4.1$ ulimit -n 2048
-bash: ulimit: open files: cannot modify limit: Operation not permitted
-bash-4.1$ ulimit -a
core file size (blocks, -c) 0
data seg size (kbytes, -d) unlimited
scheduling priority (-e) 0
file size (blocks, -f) unlimited
pending signals (-i) 95197
max locked memory (kbytes, -l) 64
max memory size (kbytes, -m) unlimited
open files (-n) 1024
pipe size (512 bytes, -p) 8
POSIX message queues (bytes, -q) 819200
real-time priority (-r) 0
stack size (kbytes, -s) 10240
cpu time (seconds, -t) unlimited
max user processes (-u) unlimited
virtual memory (kbytes, -v) unlimited
file locks (-x) unlimited
AS a result their compilations all bomb out.
# cat /etc/redhat-release
Red Hat Enterprise Linux Server release 6.0 (Santiago
I've googles for hours, and so far nothing has worked. There ought to be
a simple method to allow this. Does anyone know what it is?
Best regards, z
You have "nofiles" in your /etc/security/limits.conf which should be
"nofile", could that be the issue? You don't show an attempted change
for 'nprocs' which looks right.

JR.
--
--> GNU/Linux is user friendly... it's just picky about its friends.
zedkay
2011-11-07 13:04:26 UTC
Permalink
Post by Johnny Rebel
Post by zedkay
Hi there,
I am trying to set unlimited nprocs and open files for all users on a
fingerprint-auth: session required pam_limits.so
fingerprint-auth-ac: session required pam_limits.so
password-auth: session required pam_limits.so
password-auth-ac: session required pam_limits.so
runuser:session required pam_limits.so
smartcard-auth: session required pam_limits.so
smartcard-auth-ac: session required pam_limits.so
su: session required pam_limits.so debug
sudo: session required pam_limits.so
sudo-i: session required pam_limits.so
system-auth: session required pam_limits.so debug
system-auth-ac: session required pam_limits.so debug
* soft nofiles unlimited
* hard nofiles unlimited
* hard nproc unlimited
* soft nproc unlimited
/etc/security/limits.d/90-nproc.conf
* soft nproc unlimit
# su - tomcat
-bash-4.1$ ulimit -n 2048
-bash: ulimit: open files: cannot modify limit: Operation not permitted
-bash-4.1$ ulimit -a
core file size (blocks, -c) 0
data seg size (kbytes, -d) unlimited
scheduling priority (-e) 0
file size (blocks, -f) unlimited
pending signals (-i) 95197
max locked memory (kbytes, -l) 64
max memory size (kbytes, -m) unlimited
open files (-n) 1024
pipe size (512 bytes, -p) 8
POSIX message queues (bytes, -q) 819200
real-time priority (-r) 0
stack size (kbytes, -s) 10240
cpu time (seconds, -t) unlimited
max user processes (-u) unlimited
virtual memory (kbytes, -v) unlimited
file locks (-x) unlimited
AS a result their compilations all bomb out.
# cat /etc/redhat-release
Red Hat Enterprise Linux Server release 6.0 (Santiago
I've googles for hours, and so far nothing has worked. There ought to be
a simple method to allow this. Does anyone know what it is?
Best regards, z
You have "nofiles" in your /etc/security/limits.conf which should be
"nofile", could that be the issue? You don't show an attempted change
for 'nprocs' which looks right.
JR.
Thank-you JR for this.

Amusingly, setting nofile to anything greater than 1,048,576 will
disable all log in sessions including su, so I have left this to 1,048,575

https://access.redhat.com/kb/docs/DOC-56054
--
Please do not reply to my Email address. It is a faux Email address.
Cyberpunk FPS/MMORG www.neocron.com
Runs on Windows, platinum in latest WINE/Ubuntu. Running since 2002.
Loading...