RES_DATA RES_RSS etc

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

RES_DATA RES_RSS etc

Postby vpolyakov » Thu Jan 23, 2003 7:32 pm

im trying to set these limits for the shell users.
is there an easy way to find out exactly what values to give to:
RES_DATA
RES_MEMLOCK
RES_RSS
RES_NOFILE
RES_CORE
so that the users CAN login and do useful stuff (like use pine, mutt, gcc, ssh, ftp, mail, lynx, etc)
but can NOT bring my system to its knees with something as simple and pathetic as
typing: :(){ :|:&};: at the bash prompt?

the only way that i can think of is just trial-error.. give huge values, and then lower them until they cant get lowered anymore
but that seems very tedious to me

any suggestions on how to do it another way?

using grsecurity-1.9.9-rc3 with the latest devel gradm on 2.4.20
vpolyakov
 
Posts: 7
Joined: Tue Jan 21, 2003 12:36 pm

Return to grsecurity support