On Di, 01.09.20 08:57, Joshua Miller (joshuamiller01@xxxxxxxxx) wrote: > On Tue, Sep 1, 2020 at 7:30 AM Lennart Poettering <lennart@xxxxxxxxxxxxxx> > wrote: > > Anyway, do you want this for login users or for system services? > > Initially your reference to User= suggests the latter, but your > > reference to PAM suggests the former. What is it now? > > I'm looking at system services; sorry for conflating the two. > > In this case, I'd specifically like to set MEMLOCK. It's got the property > of being accounted at the user level, > but the limit is enforced at the process level, which means if multiple > system services running > as the same user have different limits, the service with the lesser limit > can break. As mentioned, there is no construct for setting this per system user. If you want to this per-service use LimitMEMLOCK=. Lennart -- Lennart Poettering, Berlin _______________________________________________ systemd-devel mailing list systemd-devel@xxxxxxxxxxxxxxxxxxxxx https://lists.freedesktop.org/mailman/listinfo/systemd-devel